
GIAC Certified Web Application Defender
Domain 4Objective 1
AJAX Technologies and Security Strategies GWEB Practice Questions (Page 2)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 6–10
- 6
Why is logging AJAX requests important for security monitoring?
Select an answer first - 7
What is JSON hijacking?
Select an answer first - 8
A security analyst is tuning an anomaly detection system for AJAX endpoints. The system logs request parameters, user IDs, and timestamps. The analyst wants to detect credential stuffing, where an attacker tries many username/password pairs via an AJAX login endpoint. The attacker rotates IP addresses and uses random User-Agent strings. Which detection strategy is MOST effective?
Select an answer first - 9
A security team wants to detect automated AJAX scraping of a public API. The API returns JSON data and is used by a legitimate single-page app. The team notices a client making hundreds of requests per minute with a consistent `User-Agent` and no referrer. Which monitoring signal is MOST useful to distinguish this bot from a legitimate user?
Select an answer first - 10
A single-page application loads user-generated HTML content from an AJAX endpoint and displays it in a modal. The content is sanitized on the server, but the team wants to add a client-side control to limit the damage if a sanitization bypass occurs. The app already has a CSP that allows `script-src 'self'`. Which additional client-side control is MOST effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.