
GIAC Certified Web Application Defender
Domain 5Objective 2
Encryption and Protecting Sensitive Data GWEB Practice Questions (Page 7)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 31–35
- 31
Which term describes the process of converting ciphertext back into readable plaintext using the appropriate key?
Select an answer first - 32
A startup is building a mobile app that stores sensitive user data on the device. They want to protect the data with encryption. Which approach is most secure?
Select an answer first - 33
A company uses a cloud KMS to encrypt data at rest. The security policy requires that keys be rotated every 90 days and that old keys be retained for at least one year to decrypt archived data. The operations team wants to automate rotation. Which approach best meets these requirements?
Select an answer first - 34
What property does a digital signature provide that encryption alone does not?
Select an answer first - 35
A web application is hosted behind a load balancer that terminates TLS. The application itself receives plaintext HTTP traffic from the load balancer. The security team is concerned about the risk of data exposure. Which action is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.