Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 3Objective 3

Cross Origin Policy Attacks and Mitigation GWEB Practice Questions (Page 4)

Part of the Input Handling and Injection Flaws domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
7concepts

Questions 16–20

  1. 16expert · hard

    A security analyst is investigating a potential data leak. A user visits a malicious page that uses JavaScript to load an image from https://bank.example.com/account-balance. The image endpoint returns a 200 OK if the balance is over $10,000 and a 404 otherwise. The malicious page uses the image's onload/onerror events to determine the balance. Which statement best describes this attack?

    Select an answer first
  2. 17expert · hard

    A company operates a legacy web application that uses cookies for authentication and has no CSRF protection. The application is being modernized and the team wants to add CSRF defenses without breaking existing functionality. The application supports both form submissions and AJAX requests. Which combination of controls provides the most robust defense?

    Select an answer first
  3. 18expert · hard

    A legacy web application uses cookies for authentication and has many state-changing endpoints. The team wants to add CSRF protection without breaking existing functionality. Some users access the application through a reverse proxy that strips the Origin header. Which CSRF mitigation is most robust under these constraints?

    Select an answer first
  4. 19application · medium

    A user is logged into a social media site. While browsing a forum, a malicious post includes an image tag that points to the social media site's 'change email' endpoint. The browser requests the image, sending the user's session cookie. What is the primary reason this attack succeeds?

    Select an answer first
  5. 20expert · hard

    A security team is reviewing a web application that uses JSONP endpoints to support legacy integrations. They find that the application also uses cookies for authentication. Which attack is most likely to succeed due to the JSONP endpoint?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.