Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 2Objective 2

Web Application Testing Tools GWAPT Practice Questions (Page 10)

Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)

58questions here
12free pages
12concepts

Questions 46–50

  1. 46application · medium

    A penetration tester is using an automated vulnerability scanner to assess a web application. The scanner has completed its crawl and has identified several potential vulnerabilities. The tester wants to prioritize which findings to investigate manually. Which approach is most effective?

    Select an answer first
  2. 47application · medium

    You are testing a single-page application (SPA) that loads content dynamically via JavaScript. You need to identify all API endpoints the application calls and view the JSON responses. You also need to see the exact request headers sent for each call. Which tool should you use first?

    Select an answer first
  3. 48expert · hard

    A security team wants to assess the SSL/TLS configuration of their web server. They have a limited maintenance window and need to identify the most critical issues quickly. They also want to verify that the certificate is trusted by major browsers. Which tool is best for this task?

    Select an answer first
  4. 49application · medium

    You are testing a web application that uses client-side JavaScript to validate input before submission. You want to bypass the client-side validation and send a malicious payload directly to the server. Which tool is best for this?

    Select an answer first
  5. 50application · medium

    A security team is using an automated vulnerability scanner to assess a web application. The scanner's report shows a high number of 'false positives' for SQL injection in a search feature. The team wants to reduce the noise and focus on real vulnerabilities. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.