
GIAC Certified Web Application Defender
Domain 2Objective 1
Authentication GWEB Practice Questions (Page 6)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 26–30
- 26
A web application has a session timeout of 30 minutes of inactivity. A user complains that they are logged out while reading a long article. The security team wants to balance security and usability. Which approach is best?
Select an answer first - 27
A web application allows users to log in from multiple devices. The security team wants to ensure that if a user's session token is compromised, the attacker cannot use it after the user changes their password. Which control is most effective?
Select an answer first - 28
A security audit reveals that after a user changes their password, their existing session remains valid. The auditor recommends invalidating all sessions. What is the primary security benefit?
Select an answer first - 29
A bank wants to implement MFA for online banking. They already require a password. Which additional factor is an example of a possession factor?
Select an answer first - 30
Which of the following is a common method used to execute a session hijacking attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.