
GIAC Certified Web Application Defender
Domain 5Objective 3
Leading Edge Technologies and Web Security GWEB Practice Questions (Page 5)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
3concepts
Questions 21–25
- 21
A security tester is assessing a web application that uses a JavaScript framework (e.g., React) on the client side and a REST API on the server. The tester wants to identify client-side security issues. Which technique is most effective?
Select an answer first - 22
A company is planning to use a service mesh for its microservices-based web application. The security team is evaluating the security implications. Which of the following is the most important security consideration?
Select an answer first - 23
What is a security concern specific to using a GraphQL API in a web application?
Select an answer first - 24
Which technique is essential when security testing a web application that relies heavily on client-side JavaScript frameworks?
Select an answer first - 25
Which technology is most directly associated with the concept of 'serverless' computing in modern web applications?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.