
GIAC Web Application Penetration Tester
Domain 2Objective 2
Web Application Testing Tools GWAPT Practice Questions (Page 12)
Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 56–58
- 56
You are performing reconnaissance on a target organization. You have identified the main domain, but you need to find subdomains that are not indexed by search engines, such as internal tools or staging servers. You have limited time and want to maximize coverage. Which approach is most effective?
Select an answer first - 57
To use an intercepting proxy to capture HTTPS traffic from a browser, what must be installed and trusted in the browser?
Select an answer first - 58
A penetration tester wants to manually inspect and modify HTTP requests and responses in real time as they travel between the browser and the web application. Which category of tool is most appropriate?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GWAPT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.