
GIAC Web Application Penetration Tester
Domain 2Objective 2
Web Application Testing Tools GWAPT Practice Questions (Page 6)
Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 26–30
- 26
During a web application penetration test, a tester needs to automate the discovery of common vulnerabilities such as SQL injection and cross-site scripting across many pages. Which category of tool is designed for this purpose?
Select an answer first - 27
You are testing an application's session management. You captured a session cookie and want to understand its structure and see if it changes predictably across multiple logins. Which tool is most appropriate for analyzing and manipulating the cookie?
Select an answer first - 28
In browser developer tools, which panel shows the exact HTTP request headers, response headers, and timing for each network request made by the page?
Select an answer first - 29
Your automated vulnerability scanner reported a 'Reflected XSS' vulnerability in a search parameter. Before including it in the final report, you need to verify the finding and determine the exact payload that triggers the vulnerability. Which approach is most appropriate?
Select an answer first - 30
Why would a penetration tester encode a payload using Base64 before sending it to a web application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.