
GIAC Web Application Penetration Tester
Domain 5Objective 1
Web Application SQL Injection Attacks GWAPT Practice Questions (Page 3)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
Questions 11–15
- 11
A development team is remediating a SQL injection vulnerability in a Java application. The team wants to use a defense that is considered the most effective against SQL injection. Which coding practice should the team adopt?
Select an answer first - 12
A tester is exploiting a SQL injection in a MySQL application. The tester has confirmed the injection point and wants to read the contents of a file on the database server. The application's database user has FILE privilege. Which payload should the tester use?
Select an answer first - 13
A penetration tester is exploiting a SQL injection vulnerability in a product listing page. The tester wants to extract the contents of the 'users' table. The tester has already confirmed the injection point and the number of columns. Which SQL injection technique should the tester use to extract the data?
Select an answer first - 14
A security team is reviewing a web application that uses a database account with DBA privileges. The application has a SQL injection vulnerability in a product ID parameter. The team wants to implement a defense that reduces the impact of a successful injection while maintaining functionality. Which control should the team implement?
Select an answer first - 15
A security team is reviewing a web application that connects to a database using a highly privileged account. The application has multiple SQL injection vulnerabilities. Which defense-in-depth measure should the team implement to reduce the impact of a successful SQL injection attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.