Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 3Objective 3

Cross Origin Policy Attacks and Mitigation GWEB Practice Questions (Page 1)

Part of the Input Handling and Injection Flaws domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
7concepts

Questions 1–5

  1. 1application · medium

    A company is deploying a new web application that handles sensitive financial data. The security team requires defense in depth against CSRF. Which combination of controls provides the strongest protection?

    Select an answer first
  2. 2foundation · easy

    Why is using 'Access-Control-Allow-Origin: *' together with 'Access-Control-Allow-Credentials: true' considered a dangerous CORS misconfiguration?

    Select an answer first
  3. 3application · medium

    A web application sets a session cookie with SameSite=Lax. A user is logged in and visits a malicious site that attempts a cross-origin POST request to change the user's password. What happens?

    Select an answer first
  4. 4foundation · easy

    Which of the following is a best practice for mitigating cross-origin policy attacks?

    Select an answer first
  5. 5application · medium

    An application allows users to embed images from other websites using <img> tags. A security analyst warns that this could be abused to leak information. Which attack technique leverages the <img> tag to bypass the same-origin policy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.