
GIAC Certified Web Application Defender
Domain 4Objective 3
Web Services Security GWEB Practice Questions (Page 2)
Part of the Advanced Threats and Defense domain, which makes up ~27% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
10concepts
Questions 6–10
- 6
A security analyst is reviewing the logging configuration for a REST API. The API is frequently targeted by credential stuffing attacks. Which logging practice would best support detection and investigation of these attacks?
Select an answer first - 7
A company operates a public API that uses API keys for authentication. A partner's API key is compromised, and the attacker uses it to make a high volume of requests. The company's rate limiting is based on the API key. The legitimate partner also uses the same key from multiple servers. Which approach best balances security and availability?
Select an answer first - 8
What is the primary goal of rate limiting in a web service?
Select an answer first - 9
A development team is building a REST API that accepts JSON payloads. The API uses a JavaScript runtime and merges user-supplied JSON into a configuration object. A security review warns that an attacker could send a JSON payload with a key like "__proto__" to alter the object's prototype. Which mitigation is most effective?
Select an answer first - 10
A company exposes a REST API that must be accessed by a legacy client that only supports TLS 1.0. The security team requires all traffic to be encrypted. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWEB” is a trademark of its owner, used for identification only.