Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 5Objective 1

Security Testing GWEB Practice Questions (Page 6)

Part of the Security Testing and Cryptography domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 5–8 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
6concepts

Questions 26–30

  1. 26application · medium

    A development team is building a new online payment portal. The security lead wants to identify threats early in the SDLC. The team draws a data flow diagram showing the user's browser, the web server, the application server, and the payment gateway. They then use STRIDE to categorize potential threats. Which threat category is most directly associated with an attacker modifying the amount of a transaction in transit?

    Select an answer first
  2. 27application · medium

    A security analyst is using an automated vulnerability scanner on a web application. The scanner reports a cross-site scripting (XSS) vulnerability in a search field. The analyst reviews the raw HTTP request and response and sees that the input is reflected in the response without encoding. What should the analyst do to confirm the finding?

    Select an answer first
  3. 28expert · hard

    A penetration tester is testing a web application that uses a microservices architecture. The tester has found a vulnerability in one service that allows an attacker to access another service's internal API. The rules of engagement allow testing all services. What is the most important consideration when reporting this finding?

    Select an answer first
  4. 29foundation · easy

    Which element is essential for defining the success criteria of a security test?

    Select an answer first
  5. 30application · medium

    A vulnerability scan of a web application reports a large number of 'medium' severity findings. The security analyst reviews the findings and notices that many are due to outdated JavaScript libraries that are not actually used by the application. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.