
GIAC Web Application Penetration Tester
Domain 2Objective 2
Web Application Testing Tools GWAPT Practice Questions (Page 9)
Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 41–45
- 41
Which browser developer tools panel allows a tester to view and modify cookies?
Select an answer first - 42
Which tool in Burp Suite is used to encode and decode data?
Select an answer first - 43
What is the purpose of analyzing session tokens and cookies during a penetration test?
Select an answer first - 44
You are testing a search feature that reflects user input in the response. You want to discover input validation flaws by sending a large number of unexpected inputs, including special characters and long strings. Which tool is most appropriate for this task?
Select an answer first - 45
Your team uses an automated vulnerability scanner that reported a 'SQL Injection' finding on a login form. Before reporting this to the client, you need to confirm the finding manually and determine the exact parameter affected. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.