
GIAC Certified Web Application Defender
Domain 5Objective 3
Leading Edge Technologies and Web Security GWEB Practice Questions (Page 6)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
3concepts
Questions 26–30
- 26
A security tester is assessing a web application that uses a micro frontend architecture. The tester wants to test for cross-origin issues. Which approach is most effective?
Select an answer first - 27
A security tester is assessing a web application that uses GraphQL and has a strict rate-limiting policy. The tester wants to test for denial-of-service via complex queries. Which approach is most effective while avoiding rate-limiting?
Select an answer first - 28
A security tester is assessing a web application that uses a message queue (e.g., RabbitMQ) for asynchronous processing of user uploads. Which test is most important?
Select an answer first - 29
A company is planning to use a blockchain-based identity management system for its web application. The security team is evaluating the security implications. Which of the following is the most important security consideration?
Select an answer first - 30
A security tester is evaluating a web application that uses a NoSQL database (e.g., MongoDB) for storing user data. Which injection test is most important?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.