GIAC Web Application Penetration Tester (GWAPT) Practice Test
Build your confidence for GIAC Web Application Penetration Tester (GWAPT). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.
Try a sample questionExam overview and details
GIAC Web Application Penetration Tester exam covering OWASP vulnerabilities, web exploitation, and API security testing. Administered by GIAC as a multiple choice format exam. Key domains include Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack, Reconnaissance and Mapping, Web Application Authentication Attacks and Web Application Configuration Testing. The exam consists of 115 questions over 180 minutes.
Sample Questions
Choose an answer and explore the explanation to see how practice works.
An ORM (e.g., SQLAlchemy, Hibernate, Sequelize) wraps queries automatically. Which usage pattern STILL leaves the application vulnerable to SQL injection despite the ORM?
You confirm SSTI on a Java application using Freemarker (the `${...}` and `<#assign>` syntax both work). Which Freemarker built-in directive is the canonical RCE primitive when `freemarker.template.utility.Execute` is available, and what configuration mitigates this?
An application's `Content-Security-Policy: script-src 'self' https://www.googleapis.com` blocks inline scripts. You find HTML injection that lets you add a `` tag. Which CSP bypass is MOST likely available given this allow-list?
You are content-discovering against `https://app.target.example/` and need to fuzz directory and file paths. Which `ffuf` command provides the highest-signal initial run with reasonable defaults for a modern web app, filtering out 404 noise?
An older Lodash version (<4.17.12) is in use. The application calls _.merge({}, JSON.parse(req.body)). An attacker sends {"__proto__":{"polluted":"yes"}}. What is the resulting class of vulnerability and its impact path on a typical Express + EJS app?
Career Opportunities & Salary
Exam insights and study advice
In today's digital landscape, web applications are the primary interface for business and data exchange, making them a top target for attackers. Theoretical knowledge is insufficient against evolving threats like insecure deserialization, server-side request forgery (SSRF), and complex access control flaws. The GWAPT matters because it certifies practical, offensive security skills. Holders of this certification prove they can think like an attacker to systematically find and demonstrate real-world vulnerabilities before malicious actors do, directly contributing to the protection of sensitive data, maintaining regulatory compliance, and preserving organizational reputation.
What this exam covers
01Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack
Topics
- Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.
Learning objectives
- Demonstrate an understanding of Cross Site Request Forgery, Cross Site Scripting and Client Injection attacks and the tools and techniques used to discover and exploit vulnerabilities.
02Reconnaissance and Mapping
Topics
- Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.
Learning objectives
- Demonstrate an understanding of the techniques used to conduct discovery, exploration and investigation of a web site and web application features such as port scanning, identifying services and configurations, spidering, application flow charting and session analysis.
03Web Application Authentication Attacks
Topics
- Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.
Learning objectives
- Demonstrate a familiarity with the process and mechanisms used to secure web applications by authentication, how to enumerate users and how to bypass and exploit weak authentication.
04Web Application Configuration Testing
Topics
- Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.
Learning objectives
- Demonstrate a familiarity with the tools and techniques used to audit and identify flaws in the design or implementation in the configuration of a web site.
05Web Application Overview
Topics
- Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.
Learning objectives
- Demonstrate an understanding of the technologies, programming languages and structures that are involved in the construction and implementation of a web site such as HTTP, HTTPS and AJAX within the context of security, vulnerabilities and basic operation.
06Web Application Session Management
Topics
- Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.
Learning objectives
- Demonstrate an understanding of how a web application manages client sessions, tracks user activity and uses SSL/TLS in modern web communications as well as the attacks that can be leveraged against flaws in session state.
07Web Application SQL Injection Attacks
Topics
- Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.
Learning objectives
- Demonstrate a familiarity with the techniques used to audit and test the security of web applications using SQL injection attacks and how to identify SQL injection vulnerabilities in applications.
08Web Application Testing Tools
Topics
- Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.
Learning objectives
- Demonstrate an understanding of the tools and techniques required to perform web application security testing on modern web-based languages such as JavaScript with AJAX including the use of proxies, fuzzing, scripting, and attacking application logic.