
GIAC Web Application Penetration Tester
Domain 5Objective 1
Web Application SQL Injection Attacks GWAPT Practice Questions (Page 6)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
Questions 26–28
- 26
Which SQL injection technique is used to extract data from other database tables by combining the results of two queries?
Select an answer first - 27
A penetration tester is testing a web application that uses a search feature. The tester submits the payload ' AND SLEEP(5) -- and observes that the response takes 5 seconds longer than normal. Which detection technique is the tester using, and what does this result confirm?
Select an answer first - 28
A penetration tester is exploiting a SQL injection vulnerability in a web application. The tester wants to extract the contents of the 'users' table, but the application only displays the first row of the result set. The tester has confirmed the injection point and the number of columns. Which technique should the tester use to extract all rows from the 'users' table?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GWAPT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.