GIAC Web Application Penetration Tester (GWAPT) Practice Test

140 प्रश्न उपलब्ध

GIAC Web Application Penetration Tester (GWAPT) के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।

एक नमूना सवाल आज़माएँ
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
सर्टिफिकेशन परीक्षा
115 परीक्षा प्रश्न
3 घंटे समय सीमा
आपका अभ्यास
140 अभ्यास सवाल
2 घंटे 20 मिनट अभ्यास समय
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
पार करने की सीमा 71 इस प्रमाणन के लिए प्रकाशित उत्तीर्णांक।
GIAC से आधिकारिक उद्देश्य
GIAC140 अभ्यास प्रश्नबैंक 2026-07-24 को अपडेट हुआ
ब्लूप्रिंट सत्यापितGIAC official objectives के साथ जाँचा गयामेटाडेटा सत्यापित 2026-03-18हम कैसे सत्यापित करते हैं

परीक्षा का परिचय और विवरण

GIAC Web Application Penetration Tester exam covering OWASP vulnerabilities, web exploitation, and API security testing. Administered by GIAC as a multiple choice format exam. Key domains include Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack, Reconnaissance and Mapping, Web Application Authentication Attacks and Web Application Configuration Testing. The exam consists of 115 questions over 180 minutes.

नमूना प्रश्न

अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।

Web Application SQL Injection Attacks

An ORM (e.g., SQLAlchemy, Hibernate, Sequelize) wraps queries automatically. Which usage pattern STILL leaves the application vulnerable to SQL injection despite the ORM?

Server-Side Template Injection

You confirm SSTI on a Java application using Freemarker (the `${...}` and `<#assign>` syntax both work). Which Freemarker built-in directive is the canonical RCE primitive when `freemarker.template.utility.Execute` is available, and what configuration mitigates this?

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

An application's `Content-Security-Policy: script-src 'self' https://www.googleapis.com` blocks inline scripts. You find HTML injection that lets you add a `` tag. Which CSP bypass is MOST likely available given this allow-list?

Reconnaissance and Mapping

You are content-discovering against `https://app.target.example/` and need to fuzz directory and file paths. Which `ffuf` command provides the highest-signal initial run with reasonable defaults for a modern web app, filtering out 404 noise?

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

An older Lodash version (<4.17.12) is in use. The application calls _.merge({}, JSON.parse(req.body)). An attacker sends {"__proto__":{"polluted":"yes"}}. What is the resulting class of vulnerability and its impact path on a typical Express + EJS app?

करियर के अवसर और वेतन

मध्य वेतन: $129,180US मार्केट– Information Security Analysts

स्रोत: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।

इस परीक्षा में क्या शामिल है

01Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

विषय

  • Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.

सीखने के उद्देश्य

  • Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.

02Reconnaissance and Mapping

विषय

  • Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.

सीखने के उद्देश्य

  • Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.

03Web Application Authentication Attacks

विषय

  • Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.

सीखने के उद्देश्य

  • Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.

04Web Application Configuration Testing

विषय

  • Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.

सीखने के उद्देश्य

  • Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.

05Web Application Overview

विषय

  • Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.

सीखने के उद्देश्य

  • Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.

06Web Application Session Management

विषय

  • Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.

सीखने के उद्देश्य

  • Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.

07Web Application SQL Injection Attacks

विषय

  • Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.

सीखने के उद्देश्य

  • Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.

08Web Application Testing Tools

विषय

  • Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.

सीखने के उद्देश्य

  • Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.

परीक्षा विवरण GWAPT | $949 USD | 3 घंटे

परीक्षा कोड GWAPT
विक्रेता GIAC
परीक्षा शुल्क $949 USD
उत्तीर्ण अंक 71
समय सीमा 3 घंटे
परीक्षा प्रश्न 115
प्रश्न प्रकारअभी इस भाषा में उपलब्ध नहीं है
पुनः परीक्षा नीति Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
परीक्षा प्रारूप Multiple Choice
ऑनलाइन निगरानी उपलब्ध

अक्सर पूछे जाने वाले प्रश्न

क्या GWAPT के लिए भारी प्रोग्रामिंग या स्क्रिप्टिंग अनुभव की आवश्यकता है?

परीक्षा में प्रयास करने से पहले कितनी हैंड्स-ऑन लैब कार्य की आवश्यकता है?

क्या GWAPT आधुनिक API सुरक्षा को कवर करता है?

उभरते खतरों के साथ परीक्षा सामग्री कितनी वर्तमान है?

परीक्षा के व्यावहारिक, परिदृश्य-आधारित प्रश्नों का सामना करने के लिए सबसे अच्छी रणनीति क्या है?