Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 4Objective 1

AJAX Technologies and Security Strategies GWEB Practice Questions (Page 5)

Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
8concepts

Questions 21–25

  1. 21application · medium

    A mobile banking web app uses AJAX to send account balances and transaction details. The app is served over HTTPS, but the API also responds to plain HTTP requests. A security review flags that sensitive data could be intercepted. Which action is MOST effective to protect data in transit?

    Select an answer first
  2. 22foundation · easy

    Which attack involves an attacker adding extra parameters with the same name to an AJAX request to override or manipulate the intended parameter value?

    Select an answer first
  3. 23foundation · easy

    What is the primary security benefit of using HTTPS for AJAX requests?

    Select an answer first
  4. 24foundation · easy

    What is the purpose of output encoding in the context of AJAX security?

    Select an answer first
  5. 25foundation · easy

    Which security vulnerability is commonly associated with AJAX when a web application does not properly validate or encode data that is inserted into the DOM?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.