
GIAC Certified Web Application Defender
Domain 4Objective 2
Modern Application Framework Issues and Serialization GWEB Practice Questions (Page 4)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 16–20
- 16
In the context of application security, what does serialization primarily do?
Select an answer first - 17
A penetration tester is assessing a Java application that deserializes data from a user-controlled cookie. The application has a filter that rejects cookies containing the string 'org.apache.commons.collections'. The tester wants to bypass the filter. Which approach is most likely to succeed?
Select an answer first - 18
Which code pattern is a strong indicator of unsafe deserialization?
Select an answer first - 19
A Python web application receives a serialized object from a message queue. The object is used to update user profiles. The team wants to prevent deserialization attacks while minimizing code changes. Which approach should they choose?
Select an answer first - 20
A security analyst is investigating a suspected deserialization attack on a .NET application. The application uses BinaryFormatter to deserialize data from a message queue. The analyst finds that the application has a custom SerializationBinder that restricts types to a specific namespace. However, the attack succeeded. What is the most likely reason?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.