
GIAC Certified Web Application Defender
Domain 5Objective 2
Encryption and Protecting Sensitive Data GWEB Practice Questions (Page 2)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 6–10
- 6
A developer is designing a password storage mechanism for a new web application. They want to store passwords in a way that resists offline brute-force attacks. Which approach should they choose?
Select an answer first - 7
Why is it important to securely store cryptographic keys separately from the encrypted data?
Select an answer first - 8
What is the purpose of data protection regulations like GDPR in relation to encryption?
Select an answer first - 9
An organization uses a centralized key management service (KMS) to encrypt sensitive data. A developer accidentally exposes a data encryption key (DEK) in a log file. What is the best course of action?
Select an answer first - 10
A security analyst is investigating a potential padding oracle vulnerability in a web application. The application uses AES-CBC with PKCS#7 padding. The analyst wants to confirm the vulnerability without causing a service disruption. Which test is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.