
GIAC Certified Web Application Defender
Domain 4Objective 4
File Upload, Response Readiness, Proactive Defense GWEB Practice Questions (Page 8)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
10concepts
Questions 36–40
- 36
In a patch management process, what is the purpose of prioritizing patches?
Select an answer first - 37
An attacker uploads a file named `shell.php.jpg` to a server that processes files based on the last extension. Which file upload bypass technique is being used?
Select an answer first - 38
Which WAF rule category is designed to detect and block SQL injection attempts?
Select an answer first - 39
A company runs a web application on a content management system (CMS) that frequently releases security patches. The team is struggling to keep up with patching. Which approach BEST prioritizes which patches to apply first?
Select an answer first - 40
An attacker uploads a file that exploits a vulnerability in the server's image-processing library. What type of file upload attack vector is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.