
GIAC Certified Web Application Defender
Domain 4Objective 1
AJAX Technologies and Security Strategies GWEB Practice Questions (Page 9)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 41–45
- 41
A security analyst is setting up logging for an AJAX endpoint that handles password changes. The endpoint accepts the current password, new password, and a CSRF token. Which logging practice is most appropriate?
Select an answer first - 42
A web application uses AJAX to submit a login form. The developer wants to protect the credentials from being exposed in browser history and from being logged by proxy servers. Which approach is MOST appropriate?
Select an answer first - 43
A mobile web application uses AJAX to send user credentials to a login endpoint. The application is served over HTTPS, but the login endpoint is also accessible over HTTP due to a misconfiguration. Which control should be implemented to ensure credentials are never transmitted in plaintext?
Select an answer first - 44
Which control should be applied to an AJAX endpoint to ensure that only authenticated users can access it?
Select an answer first - 45
Which technology is the traditional JavaScript API used to make asynchronous HTTP requests from a web browser without reloading the page?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.