Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Web Application Defender

Domain 2Objective 2

Session Security & Business Logic GWEB Practice Questions (Page 2)

Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
12concepts

Questions 6–10

  1. 6foundation · easy

    Which of the following is a secure way to store a session identifier on the client side?

    Select an answer first
  2. 7foundation · easy

    Why is it important to clear the session cookie on the client side during logout?

    Select an answer first
  3. 8application · medium

    A web application allows users to log in and then access a dashboard. During a penetration test, an assessor discovers that the application accepts a session ID supplied in the URL query string and does not change the session ID after successful authentication. Which combination of controls should the development team implement to directly mitigate the identified risks?

    Select an answer first
  4. 9foundation · easy

    Which of the following is a test for session fixation vulnerability?

    Select an answer first
  5. 10foundation · easy

    What is a recommended preventive measure against session hijacking?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.