GIAC Web Application Penetration Tester (GWAPT) Practice Test

140 preguntas disponibles

Gana confianza para GIAC Web Application Penetration Tester (GWAPT). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
115 Preguntas del examen
3 horas Límite de Tiempo
Tu práctica
140 Preguntas de práctica
2 horas 20 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 71 Puntuación mínima publicada para obtener esta certificación.
Objetivos oficiales de GIAC
GIAC140 preguntas de prácticaBanco actualizado el 2026-07-24
Temario verificadoVerificado con GIAC official objectivesMetadatos verificados 2026-03-18Cómo verificamos

Descripción y detalles del examen

GIAC Web Application Penetration Tester exam covering OWASP vulnerabilities, web exploitation, and API security testing. Administered by GIAC as a multiple choice format exam. Key domains include Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack, Reconnaissance and Mapping, Web Application Authentication Attacks and Web Application Configuration Testing. The exam consists of 115 questions over 180 minutes.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

Web Application SQL Injection Attacks

An ORM (e.g., SQLAlchemy, Hibernate, Sequelize) wraps queries automatically. Which usage pattern STILL leaves the application vulnerable to SQL injection despite the ORM?

Server-Side Template Injection

You confirm SSTI on a Java application using Freemarker (the `${...}` and `<#assign>` syntax both work). Which Freemarker built-in directive is the canonical RCE primitive when `freemarker.template.utility.Execute` is available, and what configuration mitigates this?

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

An application's `Content-Security-Policy: script-src 'self' https://www.googleapis.com` blocks inline scripts. You find HTML injection that lets you add a `` tag. Which CSP bypass is MOST likely available given this allow-list?

Reconnaissance and Mapping

You are content-discovering against `https://app.target.example/` and need to fuzz directory and file paths. Which `ffuf` command provides the highest-signal initial run with reasonable defaults for a modern web app, filtering out 404 noise?

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

An older Lodash version (<4.17.12) is in use. The application calls _.merge({}, JSON.parse(req.body)). An attacker sends {"__proto__":{"polluted":"yes"}}. What is the resulting class of vulnerability and its impact path on a typical Express + EJS app?

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

01Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

Temas

  • Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.

Objetivos de aprendizaje

  • Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.

02Reconnaissance and Mapping

Temas

  • Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.

Objetivos de aprendizaje

  • Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.

03Web Application Authentication Attacks

Temas

  • Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.

Objetivos de aprendizaje

  • Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.

04Web Application Configuration Testing

Temas

  • Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.

Objetivos de aprendizaje

  • Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.

05Web Application Overview

Temas

  • Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.

Objetivos de aprendizaje

  • Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.

06Web Application Session Management

Temas

  • Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.

Objetivos de aprendizaje

  • Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.

07Web Application SQL Injection Attacks

Temas

  • Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.

Objetivos de aprendizaje

  • Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.

08Web Application Testing Tools

Temas

  • Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.

Objetivos de aprendizaje

  • Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.

Detalles del Examen GWAPT | $949 USD | 3 horas

Código del Examen GWAPT
Proveedor GIAC
Costo del Examen $949 USD
Puntaje Mínimo 71
Límite de Tiempo 3 horas
Preguntas del examen 115
Tipos de PreguntasAún no disponible en este idioma
Política de Repetición Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Formato del Examen Multiple Choice
Supervisión en Línea Disponible

Preguntas Frecuentes

¿Se requiere experiencia en programación o scripting pesada para el GWAPT?

¿Cuánto trabajo práctico en laboratorio es necesario antes de intentar el examen?

¿Cubre el GWAPT la seguridad de API modernas?

¿Qué tan actual es el material del examen con respecto a las amenazas emergentes?

¿Cuál es la mejor estrategia para abordar las preguntas prácticas basadas en escenarios del examen?