
GIAC Certified Web Application Defender
Domain 3Objective 3
Cross Origin Policy Attacks and Mitigation GWEB Practice Questions (Page 1)
Part of the Input Handling and Injection Flaws domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
7concepts
Questions 1–5
- 1
A company is deploying a new web application that handles sensitive financial data. The security team requires defense in depth against CSRF. Which combination of controls provides the strongest protection?
Select an answer first - 2
Why is using 'Access-Control-Allow-Origin: *' together with 'Access-Control-Allow-Credentials: true' considered a dangerous CORS misconfiguration?
Select an answer first - 3
A web application sets a session cookie with SameSite=Lax. A user is logged in and visits a malicious site that attempts a cross-origin POST request to change the user's password. What happens?
Select an answer first - 4
Which of the following is a best practice for mitigating cross-origin policy attacks?
Select an answer first - 5
An application allows users to embed images from other websites using <img> tags. A security analyst warns that this could be abused to leak information. Which attack technique leverages the <img> tag to bypass the same-origin policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.