
GIAC Web Application Penetration Tester
Domain 2Objective 2
Web Application Testing Tools GWAPT Practice Questions (Page 2)
Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 6–10
- 6
You are testing an application's session management. You captured a session cookie and want to determine if it is predictable. You have collected multiple session tokens from different logins. Which tool is best for analyzing the tokens for patterns?
Select an answer first - 7
During a penetration test, a tester wants to discover hidden directories and files on a web server that are not linked from the main pages. The tester also wants to see if these resources are accessible without authentication. Which tool is best for this task?
Select an answer first - 8
You are testing a file upload feature that blocks files containing the string '<script>'. You want to bypass the filter by encoding the payload. Which tool is best for encoding the payload into a format that might bypass the filter?
Select an answer first - 9
A penetration tester is assessing an organization's external attack surface. The tester wants to identify all subdomains of the main domain to find additional web applications that may be less secure. Which tool is most appropriate for this task?
Select an answer first - 10
You need to test how a server responds to a specific HTTP method (e.g., PUT) on a particular endpoint. You want to send a raw HTTP request with custom headers and a body, and see the exact response. Which tool is best for this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.