GIAC GWAPT Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Schwachstellen in Webanwendungen | - Cross-Site Scripting (XSS) - Injektionsangriffe (SQL, NoSQL, Befehlsinjektion) - Cross-Site Request Forgery (CSRF) |
| Thema 2: Angriffe auf Webanwendungen und deren Ausnutzung | - OWASP Top 10-Schwachstellen - Schwachstellen der Geschäftslogik - Mängel bei Zugriffskontrolle und Autorisierung |
| Thema 3: Authentifizierung und Sitzungsverwaltung | - Techniken zur Umgehung der Authentifizierung - Sitzungsübernahme und Sitzungsfixierung |
| Thema 4: Grundlagen der Webanwendungssicherheit | - Client-Server-Modell und Webanwendungskomponenten - HTTP/HTTPS-Protokolle und Webanwendungsarchitektur |
| Thema 5: Methodik des Penetrationstests für Webanwendungen | - Aufklärung und Informationsbeschaffung - Berichterstellung und Dokumentation - Analyse und Ausnutzung von Schwachstellen |
GIAC Web Application Penetration Tester GWAPT GWAPT Prüfungsfragen mit Lösungen
While spidering a web application, you notice an endpoint /debug/logs. How should you proceed?
- A. Report the finding and conclude testing
- B. Exploit cross-origin resource sharing
- C. Conduct a SQL injection test
- D. Attempt to access the endpoint to gather debug information
Which technique is commonly used to identify active services running on a web server?
- A. Brute-forcing login credentials
- B. Port scanning
- C. Creating phishing emails
- D. Exploiting stored XSS vulnerabilities
Which encoding method should be used to safely display user input in HTML content?
- A. Base64 encoding
- B. URL encoding
- C. Hex encoding
- D. HTML entity encoding
What are typical signs of a successful brute-force attack? (Choose two)
- A. Increased CPU utilization
- B. Repeated login failures in the logs
- C. Outdated SSL certificates
- D. Unauthorized access to restricted resources
What common configuration errors can expose sensitive data? (Choose two)
- A. Enabling the SameSite attribute for cookies
- B. Implementing secure authentication mechanisms
- C. Using outdated SSL/TLS protocols
- D. Storing sensitive data in plaintext






1642 Kundenbewertungen

