GIAC Web Application Penetration Tester GWAPT - GWAPT Exam Practice Test
Question 1
Which web technologies are considered part of a web application frontend? (Choose two)
Correct Answer: C,D
Question 2
Which tool is commonly used as a web application proxy for penetration testing?
Correct Answer: D
Question 3
You discover that a web application stores passwords in plaintext. What is the recommended remediation?
Correct Answer: C
Question 4
What are effective methods to protect against Cross-Site Request Forgery (CSRF) attacks?
(Choose two)
(Choose two)
Correct Answer: A,B
Question 5
Which attribute of cookies helps prevent Cross-Site Scripting (XSS) attacks?
Correct Answer: C
Question 6
Which tools are effective for discovering XSS vulnerabilities? (Choose two)
Correct Answer: C,D
Question 7
In a Reflected Cross-Site Scripting attack, where is the malicious payload executed?
Correct Answer: D
Question 8
During a security assessment, you find that verbose error messages are enabled. What is the immediate action you should recommend?
Correct Answer: D
Question 9
Which features help protect against SQL injection attacks? (Choose two)
Correct Answer: C,D
Question 10
What are the outputs of performing a web application mapping process? (Choose two)
Correct Answer: A,D

