
GIAC Certified Web Application Defender
Domain 4Objective 2
Modern Application Framework Issues and Serialization GWEB Practice Questions (Page 1)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 1–5
- 1
A development team is building a microservice that receives serialized data from multiple internal services. The data is in a custom binary format that is deserialized using a third-party library. The team wants to prevent deserialization attacks without changing the data format. Which control should they implement?
Select an answer first - 2
Which of the following is an effective mitigation against insecure deserialization?
Select an answer first - 3
What is a recommended practice to prevent deserialization attacks when an application must accept serialized data?
Select an answer first - 4
A team is migrating a legacy Java application that deserializes data from a trusted internal service. They want to maintain compatibility but reduce the risk of insecure deserialization. Which approach is the best balance?
Select an answer first - 5
Which of the following is an example of a modern framework vulnerability caused by insecure defaults?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.