
GIAC Certified Web Application Defender
Domain 5Objective 2
Encryption and Protecting Sensitive Data GWEB Practice Questions (Page 9)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 41–45
- 41
Two servers need to exchange sensitive configuration data over a private network. They use a pre-shared key for encryption. The security team wants to minimize the risk of key compromise. Which practice is most important?
Select an answer first - 42
A company processes credit card data and must comply with PCI DSS. They are designing a new payment page. Which combination of controls is required?
Select an answer first - 43
In asymmetric encryption, which key is used to encrypt data that only the intended recipient can decrypt?
Select an answer first - 44
A company is implementing a secure messaging system. They need to ensure that messages are confidential and that recipients can verify the sender's identity. They also want to minimize the performance impact of encrypting large messages. Which approach should they use?
Select an answer first - 45
A company processes personal data of EU citizens and must comply with GDPR. They store data in a cloud database. Which measure is required to protect the data at rest?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.