GIAC Web Application Penetration Tester (GWAPT) Practice Test
Gana confianza para GIAC Web Application Penetration Tester (GWAPT). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.
Probar una preguntaDescripción y detalles del examen
GIAC Web Application Penetration Tester exam covering OWASP vulnerabilities, web exploitation, and API security testing. Administered by GIAC as a multiple choice format exam. Key domains include Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack, Reconnaissance and Mapping, Web Application Authentication Attacks and Web Application Configuration Testing. The exam consists of 115 questions over 180 minutes.
Preguntas de Muestra
Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.
An ORM (e.g., SQLAlchemy, Hibernate, Sequelize) wraps queries automatically. Which usage pattern STILL leaves the application vulnerable to SQL injection despite the ORM?
You confirm SSTI on a Java application using Freemarker (the `${...}` and `<#assign>` syntax both work). Which Freemarker built-in directive is the canonical RCE primitive when `freemarker.template.utility.Execute` is available, and what configuration mitigates this?
An application's `Content-Security-Policy: script-src 'self' https://www.googleapis.com` blocks inline scripts. You find HTML injection that lets you add a `` tag. Which CSP bypass is MOST likely available given this allow-list?
You are content-discovering against `https://app.target.example/` and need to fuzz directory and file paths. Which `ffuf` command provides the highest-signal initial run with reasonable defaults for a modern web app, filtering out 404 noise?
An older Lodash version (<4.17.12) is in use. The application calls _.merge({}, JSON.parse(req.body)). An attacker sends {"__proto__":{"polluted":"yes"}}. What is the resulting class of vulnerability and its impact path on a typical Express + EJS app?
Oportunidades profesionales y salario
Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.
Qué temas cubre este examen
01Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack
Temas
- Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.
Objetivos de aprendizaje
- Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.
02Reconnaissance and Mapping
Temas
- Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.
Objetivos de aprendizaje
- Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.
03Web Application Authentication Attacks
Temas
- Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.
Objetivos de aprendizaje
- Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.
04Web Application Configuration Testing
Temas
- Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.
Objetivos de aprendizaje
- Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.
05Web Application Overview
Temas
- Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.
Objetivos de aprendizaje
- Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.
06Web Application Session Management
Temas
- Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.
Objetivos de aprendizaje
- Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.
07Web Application SQL Injection Attacks
Temas
- Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.
Objetivos de aprendizaje
- Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.
08Web Application Testing Tools
Temas
- Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.
Objetivos de aprendizaje
- Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.