
GIAC Certified Web Application Defender
Domain 4Objective 1
AJAX Technologies and Security Strategies GWEB Practice Questions (Page 5)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 21–25
- 21
A mobile banking web app uses AJAX to send account balances and transaction details. The app is served over HTTPS, but the API also responds to plain HTTP requests. A security review flags that sensitive data could be intercepted. Which action is MOST effective to protect data in transit?
Select an answer first - 22
Which attack involves an attacker adding extra parameters with the same name to an AJAX request to override or manipulate the intended parameter value?
Select an answer first - 23
What is the primary security benefit of using HTTPS for AJAX requests?
Select an answer first - 24
What is the purpose of output encoding in the context of AJAX security?
Select an answer first - 25
Which security vulnerability is commonly associated with AJAX when a web application does not properly validate or encode data that is inserted into the DOM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.