GIAC Web Application Penetration Tester (GWAPT) Practice Test

140 questions available

Build your confidence for GIAC Web Application Penetration Tester (GWAPT). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
115 Exam questions
3 hours Time Limit
Your practice
140 Practice questions
2 hours 20 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 71 Published passing score for this certification.
Official objectives from GIAC
GIAC140 practice questionsBank updated 2026-07-24
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-03-18How we verify

Exam overview and details

GIAC Web Application Penetration Tester exam covering OWASP vulnerabilities, web exploitation, and API security testing. Administered by GIAC as a multiple choice format exam. Key domains include Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack, Reconnaissance and Mapping, Web Application Authentication Attacks and Web Application Configuration Testing. The exam consists of 115 questions over 180 minutes.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Web Application SQL Injection Attacks

An ORM (e.g., SQLAlchemy, Hibernate, Sequelize) wraps queries automatically. Which usage pattern STILL leaves the application vulnerable to SQL injection despite the ORM?

Server-Side Template Injection

You confirm SSTI on a Java application using Freemarker (the `${...}` and `<#assign>` syntax both work). Which Freemarker built-in directive is the canonical RCE primitive when `freemarker.template.utility.Execute` is available, and what configuration mitigates this?

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

An application's `Content-Security-Policy: script-src 'self' https://www.googleapis.com` blocks inline scripts. You find HTML injection that lets you add a `` tag. Which CSP bypass is MOST likely available given this allow-list?

Reconnaissance and Mapping

You are content-discovering against `https://app.target.example/` and need to fuzz directory and file paths. Which `ffuf` command provides the highest-signal initial run with reasonable defaults for a modern web app, filtering out 404 noise?

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

An older Lodash version (<4.17.12) is in use. The application calls _.merge({}, JSON.parse(req.body)). An attacker sends {"__proto__":{"polluted":"yes"}}. What is the resulting class of vulnerability and its impact path on a typical Express + EJS app?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

In today's digital landscape, web applications are the primary interface for business and data exchange, making them a top target for attackers. Theoretical knowledge is insufficient against evolving threats like insecure deserialization, server-side request forgery (SSRF), and complex access control flaws. The GWAPT matters because it certifies practical, offensive security skills. Holders of this certification prove they can think like an attacker to systematically find and demonstrate real-world vulnerabilities before malicious actors do, directly contributing to the protection of sensitive data, maintaining regulatory compliance, and preserving organizational reputation.

What this exam covers

01Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack

Topics

  • Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.

Learning objectives

  • Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.

02Reconnaissance and Mapping

Topics

  • Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.

Learning objectives

  • Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.

03Web Application Authentication Attacks

Topics

  • Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.

Learning objectives

  • Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.

04Web Application Configuration Testing

Topics

  • Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.

Learning objectives

  • Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.

05Web Application Overview

Topics

  • Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.

Learning objectives

  • Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.

06Web Application Session Management

Topics

  • Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.

Learning objectives

  • Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.

07Web Application SQL Injection Attacks

Topics

  • Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.

Learning objectives

  • Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.

08Web Application Testing Tools

Topics

  • Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.

Learning objectives

  • Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.

Exam Details GWAPT | $949 USD | 3 hours

Exam Code GWAPT
Vendor GIAC
Exam Cost $949 USD
Passing Score 71
Time Limit 3 hours
Exam questions 115
Question Typesperformance-based
Retake Policy Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Exam Format Multiple Choice
Online Proctoring Available

Frequently Asked Questions

Is heavy programming or scripting experience required for the GWAPT?

How much hands-on lab work is necessary before attempting the exam?

Does the GWAPT cover modern API security?

How current is the exam material with emerging threats?

What is the best strategy for tackling the exam's practical, scenario-based questions?