
GIAC Certified Web Application Defender
Domain 2Objective 1
Authentication GWEB Practice Questions (Page 8)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
10concepts
Questions 36–40
- 36
Which statement correctly distinguishes authentication from identification in a web application context?
Select an answer first - 37
A penetration test reveals that a web application accepts session tokens that were issued before a user's password change. The application also does not rotate the session token after login. Which two vulnerabilities are present?
Select an answer first - 38
In a typical web application, where is the session token stored on the client side?
Select an answer first - 39
A user logs into a web application and is presented with a dashboard showing their personal data. Which of the following describes what the application is doing when it displays the user's data?
Select an answer first - 40
A developer is building a login system and is confused about the difference between authentication and authorization. In the system, after a user logs in, they are assigned a role that determines which pages they can access. Which statement correctly describes the relationship?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.