
GIAC Certified Web Application Defender
Domain 5Objective 1
Security Testing GWEB Practice Questions (Page 3)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 11–15
- 11
A vulnerability scanner has flagged a potential file inclusion vulnerability in a web application. The application is legacy and the code is not well documented. What is the most appropriate next step?
Select an answer first - 12
What is the purpose of defining 'rules of engagement' in a security test plan?
Select an answer first - 13
A security team is planning a penetration test for a web application that is hosted in a cloud environment. The test must not affect other tenants sharing the same infrastructure. Which constraint is most important to include in the rules of engagement?
Select an answer first - 14
A penetration test has identified a critical vulnerability in a web application. The development team wants to fix it immediately, but the security team wants to document the finding first. Which approach is most appropriate?
Select an answer first - 15
After completing a web application security assessment, a tester has a list of findings that includes a critical SQL injection, a medium-severity XSS, and a low-severity information disclosure in an error page. The report must be useful to both executives and developers. How should the tester present the findings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.