
GIAC Certified Web Application Defender
Domain 1Objective 2
Web Architecture and Configuration GWEB Practice Questions (Page 5)
Part of the Web Application Foundations domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 6–10 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)
56questions here
12free pages
10concepts
Questions 21–25
- 21
Which mechanism is commonly used to maintain session state by storing a small piece of data on the client that is sent with each HTTP request?
Select an answer first - 22
A web server is configured to support both HTTP and HTTPS. The server has a valid TLS certificate for the domain 'example.com'. A user reports that when they type 'example.com' in the browser, they are redirected to 'https://example.com' but the browser shows a certificate warning. Which configuration is the most likely cause?
Select an answer first - 23
A web application uses a session cookie that is set without the Secure flag. The application is accessible over both HTTP and HTTPS. A user logs in over HTTPS, and the session cookie is set. Later, the user visits an HTTP page on the same site. Which attack is the most likely to occur?
Select an answer first - 24
Which layer in a web application architecture is responsible for managing the communication between the application logic and the data storage?
Select an answer first - 25
In a typical three-tier web application architecture, which component is responsible for executing business logic and coordinating data access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.