Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 2Objective 2

Web Application Testing Tools GWAPT Practice Questions (Page 1)

Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
12concepts

Questions 1–5

  1. 1foundation · easy

    Which tool includes a built-in web crawler for mapping web applications?

    Select an answer first
  2. 2foundation · easy

    Which tool is commonly used for fuzzing web application inputs?

    Select an answer first
  3. 3application · medium

    You are testing a REST API endpoint that accepts JSON input. You want to discover how the server handles malformed JSON, unexpected data types, and extra fields. Which tool is best for sending a variety of malformed JSON payloads?

    Select an answer first
  4. 4application · medium

    During a web application test, you need to capture a login request that uses HTTPS, modify the password parameter to test for SQL injection, and then resend the modified request multiple times with different payloads. You also need to see the raw request and response headers. Which tool is best suited for this task?

    Select an answer first
  5. 5foundation · easy

    Which command-line tool is commonly used to craft and send HTTP requests with custom headers and data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.