Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 4Objective 4

File Upload, Response Readiness, Proactive Defense GWEB Practice Questions (Page 2)

Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
10concepts

Questions 6–10

  1. 6expert · hard

    A company has a web application with a critical remote code execution vulnerability in a third-party library. The vendor has released a patch, but the patch requires a restart of the application, which will cause downtime. The application is business-critical and cannot afford downtime during peak hours. Which approach BEST balances security and availability?

    Select an answer first
  2. 7expert · hard

    A web application development team is adopting a proactive defense strategy. They have limited budget and need to choose between implementing a WAF, conducting regular penetration tests, or establishing a threat modeling process. Which option provides the MOST comprehensive proactive benefit?

    Select an answer first
  3. 8application · medium

    A web application allows users to upload images. The server-side validation checks that the file extension is in a whitelist (.jpg, .png, .gif) and that the MIME type from the Content-Type header is an image type. An attacker successfully uploads a file named 'photo.jpg.php' and executes it. Which bypass technique did the attacker likely use, and what is the most effective defense?

    Select an answer first
  4. 9application · medium

    A web application allows file uploads and uses a blacklist to block extensions like .php, .asp, and .exe. A penetration tester bypassed the filter by uploading a file named 'shell.phtml'. Why did the blacklist fail?

    Select an answer first
  5. 10foundation · easy

    What is the primary goal of content-type spoofing in a file upload attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.