
GIAC Certified Web Application Defender
Domain 5Objective 1
Security Testing GWEB Practice Questions (Page 5)
Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
6concepts
Questions 21–25
- 21
What is the primary purpose of a security test report?
Select an answer first - 22
A penetration tester is assessing a web application that uses a Web Application Firewall (WAF). The tester wants to bypass the WAF to test the underlying application. Which approach is most effective?
Select an answer first - 23
Which activity is typically performed during the 'exploitation' phase of a penetration test?
Select an answer first - 24
A security team is planning a penetration test for a web application that is hosted in a cloud environment. The application is business-critical and has a strict SLA. The team must balance thorough testing with the risk of disrupting operations. Which approach best addresses this constraint?
Select an answer first - 25
A security architect is threat modeling a new web application that will handle sensitive financial data. The team has limited time and budget. The architect must choose between a full STRIDE analysis and a focused attack-tree analysis. The application has a complex authentication flow and a simple data storage design. Which approach is more appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.