
GIAC Certified Web Application Defender
Domain 2Objective 2
Session Security & Business Logic GWEB Practice Questions (Page 3)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 11–15
- 11
A security tester is assessing a web application's session management. The tester collects 1000 session IDs and finds that they are all sequential numbers. Which vulnerability does this indicate?
Select an answer first - 12
A user logs out of a web application on a shared computer. The application clears the session cookie on the client but does not invalidate the server-side session. What is the primary risk?
Select an answer first - 13
When should a new session identifier be issued to a user?
Select an answer first - 14
A security team is investigating a possible session hijacking incident. The application uses IP binding and user-agent checks. The legitimate user's session was used from a different IP address and a different user-agent, but the application did not terminate the session. Which additional control would be most effective in detecting and responding to this type of hijacking?
Select an answer first - 15
What is the primary advantage of storing session data on the server rather than in a client-side cookie?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.