Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 2Objective 1

Authentication GWEB Practice Questions (Page 9)

Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)

55questions here
11free pages
10concepts

Questions 41–45

  1. 41expert · hard

    A company is deploying MFA for a legacy web application that only supports username/password. The security team is evaluating options: (1) SMS one-time codes, (2) a mobile authenticator app with TOTP, (3) hardware security keys via WebAuthn. The user base includes employees in areas with poor cellular connectivity, and the company cannot issue hardware tokens to all employees immediately. Which option provides the best balance of security and usability under these constraints?

    Select an answer first
  2. 42application · easy

    A security auditor is reviewing an authentication system that uses a password and a fingerprint scan. Which statement correctly classifies these factors?

    Select an answer first
  3. 43application · easy

    A web application uses a session cookie to maintain state. The security team wants to ensure that the session token is not exposed to cross-site scripting attacks. Which configuration is most effective?

    Select an answer first
  4. 44foundation · easy

    A user provides a username and password to access an application. After successful verification, the application determines that the user is allowed to view only their own profile and not other users' profiles. Which two security concepts are being demonstrated in this scenario?

    Select an answer first
  5. 45application · medium

    A web application currently uses only a username and password for login. After a phishing incident, management mandates that all users must provide a second factor that is not easily phishable. The team wants to minimize friction and avoid requiring users to install a separate app. Which approach best satisfies the requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.