
GIAC Web Application Penetration Tester
Domain 2Objective 2
Web Application Testing Tools GWAPT Practice Questions (Page 7)
Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 31–35
- 31
A tester is trying to bypass a WAF that blocks requests containing the string 'SELECT' in the query parameter. The tester wants to send a SQL injection payload that the WAF does not recognize but the application decodes. Which approach is most effective?
Select an answer first - 32
Why is subdomain enumeration important during a web application penetration test?
Select an answer first - 33
A tester is fuzzing a web application's REST API. The API accepts JSON input and returns error messages that include the input value. The tester wants to discover if the API is vulnerable to reflected XSS. The tester has limited time and must choose a fuzzing strategy. Which approach is most effective?
Select an answer first - 34
You need to automatically map all pages and endpoints of a web application, including forms and links, to understand its structure before manual testing. Which tool is most appropriate?
Select an answer first - 35
What is the primary purpose of directory and file enumeration tools like gobuster or dirb?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.