
GIAC Certified Web Application Defender
Domain 1Objective 1
Web Application and HTTP Basics GWEB Practice Questions (Page 9)
Part of the Web Application Foundations domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
9concepts
Questions 41–45
- 41
In an HTTP request line such as `POST /api/login HTTP/1.1`, which part identifies the resource being requested?
Select an answer first - 42
What is the role of an X.509 certificate in an HTTPS connection?
Select an answer first - 43
A security auditor is reviewing a web application's session management. The application sets a session cookie without the 'Secure' attribute, but the site is accessible over both HTTP and HTTPS. What is the most significant risk?
Select an answer first - 44
Which HTTP status code indicates that the requested resource was not found on the server?
Select an answer first - 45
In a typical three-tier web application architecture, which component is responsible for processing business logic and coordinating requests between the client and the database?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.