
GIAC Certified Web Application Defender
Domain 2Objective 2
Session Security & Business Logic GWEB Practice Questions (Page 10)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 46–50
- 46
An e-commerce application stores the user's role and account balance inside a signed cookie. A penetration tester discovers that the cookie is signed with a symmetric key that is hard-coded in the client-side JavaScript bundle. Which of the following is the most direct business logic impact of this flaw?
Select an answer first - 47
How does a session fixation attack typically work?
Select an answer first - 48
Which of the following is an acceptable method for generating a session identifier?
Select an answer first - 49
A web application allows users to log in and then access their profile. A security tester notices that the session ID is not regenerated after login, and the session cookie is set with SameSite=None. Which of the following is the most likely attack that the tester can demonstrate?
Select an answer first - 50
A user logs out of a web application, but a security review shows that the session remains active on the server for another 30 minutes. The session cookie is also not cleared on the client. Which combination of changes should be implemented?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.