
GIAC Certified Web Application Defender
Domain 1Objective 2
Web Architecture and Configuration GWEB Practice Questions (Page 10)
Part of the Web Application Foundations domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
10concepts
Questions 46–50
- 46
What is the purpose of an ORM (Object-Relational Mapping) library in a web application?
Select an answer first - 47
A web application uses a token-based authentication mechanism where the token is stored in a JavaScript variable and sent in the Authorization header. The application also uses a Content Security Policy (CSP) that allows scripts from any source. Which attack is the most likely to compromise the token?
Select an answer first - 48
A company hosts multiple web applications on a single Apache web server using name-based virtual hosting. The security team wants to ensure that requests without a valid Host header do not reach any application. Which configuration change best achieves this?
Select an answer first - 49
Which of the following is a stateless token-based authentication mechanism often used in modern web APIs?
Select an answer first - 50
An administrator is configuring a web server to host multiple websites on a single IP address. Each site needs its own TLS certificate. What is the most appropriate method to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.