
GIAC Certified Web Application Defender
Domain 2Objective 1
Authentication GWEB Practice Questions (Page 1)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 1–5
- 1
What is the primary purpose of multi-factor authentication (MFA)?
Select an answer first - 2
A developer is building a web application and needs to maintain user state after login. They decide to store the session token in a JavaScript variable. What is the primary security risk?
Select an answer first - 3
Which of the following is an example of the 'possession' authentication factor?
Select an answer first - 4
A web application has a session timeout of 30 minutes. However, users complain that they are logged out while filling out long forms. The product manager wants to reduce user frustration without significantly increasing security risk. Which approach is most appropriate?
Select an answer first - 5
A company is implementing MFA for its web application. They want to ensure that even if a user's password is phished, an attacker cannot log in. Which combination of factors should they require?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.