
GIAC Certified Web Application Defender
Domain 3Objective 2
CSRF GWEB Practice Questions (Page 4)
Part of the Input Handling and Injection Flaws domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
4concepts
Questions 16–20
- 16
Which of the following best describes the potential impact of a successful CSRF attack on a web application?
Select an answer first - 17
A web application has a feature that allows users to delete their account via a GET request to /delete-account. An attacker wants to trick a victim into deleting their account. Which attack vector is the most likely to succeed?
Select an answer first - 18
A company's web application uses a double-submit cookie pattern for CSRF defense. The application sets a random token in a cookie and also includes the same token in a hidden form field. A security review flags that the token is predictable. What is the most appropriate remediation?
Select an answer first - 19
A security analyst is explaining CSRF to a new developer. The developer asks: 'Why can't the attacker just read the CSRF token from the victim's browser?' Which response is most accurate?
Select an answer first - 20
When testing a web application for CSRF, which of the following is a key indicator that the application is vulnerable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.