
GIAC Certified Web Application Defender
Domain 4Objective 3
Web Services Security GWEB Practice Questions (Page 10)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
10concepts
Questions 46–49
- 46
A public REST API is being overwhelmed by a single client making thousands of requests per second, causing performance degradation for other users. The API uses API keys for authentication. What is the most effective immediate mitigation?
Select an answer first - 47
A company is deploying a new web service that will handle sensitive customer data. The service will be accessed over the internet. The security team requires that all data in transit be encrypted and that the server's identity be verified by clients. Which configuration is necessary?
Select an answer first - 48
A public REST API is experiencing a denial-of-service attack where a single IP address sends thousands of requests per second. The API also has legitimate users behind a corporate NAT that share a single IP address. Which rate limiting strategy is most appropriate?
Select an answer first - 49
Which of the following is a common technique to implement rate limiting in a web service?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GWEB
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.