
GIAC Certified Web Application Defender
Domain 5Objective 2
Encryption and Protecting Sensitive Data GWEB Practice Questions (Page 5)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 21–25
- 21
A security engineer is reviewing a web application that stores user passwords. The current implementation uses unsalted MD5 hashes. The engineer wants to improve security without breaking the login process. Which change is most appropriate?
Select an answer first - 22
A security engineer is reviewing a web application that uses AES in CBC mode for encrypting session tokens. The application returns different error messages for valid and invalid padding. Which attack is possible, and what is the best mitigation?
Select an answer first - 23
What is a key management best practice regarding cryptographic keys?
Select an answer first - 24
A security analyst notices that the application's TLS configuration allows CBC-mode cipher suites. The analyst is concerned about a padding oracle attack. Which mitigation should be applied?
Select an answer first - 25
Why is hashing commonly used for storing passwords instead of encryption?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.