
GIAC Certified Web Application Defender
Domain 2Objective 2
Session Security & Business Logic GWEB Practice Questions (Page 4)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 5–9 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
12concepts
Questions 16–20
- 16
Which of the following is a common method to detect session hijacking?
Select an answer first - 17
What is the most effective countermeasure against session fixation attacks?
Select an answer first - 18
A web application currently stores session data in a client-side cookie that includes the user's role and account balance. A security review recommends moving to server-side session storage. Which benefit is the primary reason for this change?
Select an answer first - 19
What must a secure logout function do on the server side?
Select an answer first - 20
A web application's logout function currently deletes the session cookie from the browser and redirects the user to the login page. However, a security review finds that the server-side session is not invalidated, and the session cookie is not cleared from the browser's cache. Which of the following is the most complete fix?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.