
GIAC Certified Web Application Defender
Domain 2Objective 2
Session Security & Business Logic GWEB Practice Questions (Page 2)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 6–10
- 6
Which of the following is a secure way to store a session identifier on the client side?
Select an answer first - 7
Why is it important to clear the session cookie on the client side during logout?
Select an answer first - 8
A web application allows users to log in and then access a dashboard. During a penetration test, an assessor discovers that the application accepts a session ID supplied in the URL query string and does not change the session ID after successful authentication. Which combination of controls should the development team implement to directly mitigate the identified risks?
Select an answer first - 9
Which of the following is a test for session fixation vulnerability?
Select an answer first - 10
What is a recommended preventive measure against session hijacking?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.