
GIAC Certified Web Application Defender
Domain 4Objective 2
Modern Application Framework Issues and Serialization GWEB Practice Questions (Page 8)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
6concepts
Questions 36–39
- 36
A security analyst is reviewing a Java web application that accepts a base64-encoded serialized object from an HTTP cookie. The application uses a common serialization library that supports object graphs. The analyst suspects an insecure deserialization vulnerability. Which observation would most strongly confirm that an attacker can achieve remote code execution?
Select an answer first - 37
A code review finds that a Java application uses ObjectInputStream.readObject() on data received from a socket. The data is a serialized object that the application expects to be a specific DTO. Which additional control would be most effective to prevent deserialization attacks?
Select an answer first - 38
A .NET application deserializes a binary payload from a message queue. The payload is a serialized object graph that may contain multiple types. The team wants to enforce a strict allow-list of types. Which approach should they use?
Select an answer first - 39
A developer is using a popular JavaScript framework that automatically binds query parameters to server-side objects. The framework has a known vulnerability that allows mass assignment. What is the most effective mitigation?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GWEB
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.