
GIAC Certified Web Application Defender
Domain 5Objective 1
Security Testing GWEB Practice Questions (Page 4)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 16–20
- 16
A security manager is planning a penetration test for a web application that is subject to PCI DSS. The test must be completed within a two-week window, and the budget is fixed. The manager must decide whether to use an external penetration testing firm or the internal security team. The internal team knows the application well but has limited time. The external firm is experienced but will need time to understand the application. Which factor is MOST important in this decision?
Select an answer first - 17
A security team is planning a security test for a web application that is being developed using an agile methodology. The team wants to integrate security testing into the CI/CD pipeline. The application is updated frequently, and the team wants to catch vulnerabilities early. Which approach best balances early detection with the risk of slowing down development?
Select an answer first - 18
A financial services company is planning a security test for its customer-facing web application. The compliance team requires that no production data be exposed to testers, but the test must validate the application's handling of sensitive customer data. The test window is limited to a weekend to avoid business disruption. Which approach best satisfies these constraints?
Select an answer first - 19
A penetration test has concluded, and the tester must write a report for both technical staff and management. Which structure is most effective?
Select an answer first - 20
A web application team is about to begin a security assessment of a customer-facing e-commerce portal. The compliance officer insists that the assessment must not disrupt production traffic, and the legal team requires a formal document that defines the scope, authorized testing windows, and emergency contacts. Which action should the team take FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.