
GIAC Web Application Penetration Tester
Domain 5Objective 1
Web Application SQL Injection Attacks GWAPT Practice Questions (Page 5)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
Questions 21–25
- 21
A penetration tester is testing a web application that uses a search feature. The application returns the same page content regardless of whether a SQL condition is true or false, but the tester observes a time delay when submitting a payload with SLEEP. Which detection technique should the tester use to confirm the vulnerability?
Select an answer first - 22
Which of the following is an example of applying the least privilege principle to mitigate the impact of SQL injection?
Select an answer first - 23
A penetration tester is exploiting a SQL injection vulnerability in a login form. The tester wants to bypass authentication without knowing a valid username or password. Which payload should the tester use in the username field?
Select an answer first - 24
A developer is reviewing code that uses an Object-Relational Mapping (ORM) framework. The developer finds a method that builds a dynamic query using string concatenation for a 'sort' parameter. Which action best addresses the risk?
Select an answer first - 25
A security team is hardening a web application that uses a database account with administrative privileges. The team is implementing parameterized queries to prevent SQL injection. Which additional measure is most important to reduce the impact of a successful injection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.