Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 5Objective 1

Security Testing GWEB Practice Questions (Page 2)

Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
6concepts

Questions 6–10

  1. 6application · medium

    After completing a penetration test, a tester needs to report a critical vulnerability to executives who are not technical. Which reporting approach is most effective?

    Select an answer first
  2. 7foundation · easy

    What distinguishes penetration testing from vulnerability scanning?

    Select an answer first
  3. 8application · medium

    A development team is building a new e-commerce feature that allows users to upload profile pictures. The security lead wants to identify potential threats before coding begins. Which threat modeling approach is most effective for this early stage?

    Select an answer first
  4. 9foundation · easy

    What is the primary purpose of security testing in the context of web application defense?

    Select an answer first
  5. 10foundation · easy

    What is the primary goal of threat modeling in the software development lifecycle?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.