GIAC GWEB Exam Overview:
| Certification Vendor: | GIAC (SANS Institute) |
|---|---|
| Exam Name: | GIAC Certified Web Application Defender (GWEB) Certification Exam |
| Exam Number: | GWEB |
| Exam Duration: | 240 minutes |
| Certificate Validity Period: | 4 years |
| Exam Format: | Proctored online or onsite exam, Multiple choice |
| Exam Price: | $949 USD (standard GIAC exam attempt; may vary by region/package) |
| Passing Score: | Approximately 73% |
| Real Exam Qty: | Approximately 106 questions |
| Available Languages: | English |
| Related Certifications: | GIAC Web Application Penetration Tester (GWAPT) GIAC Secure Software Programmer (GSSP) |
| Recommended Training: | SANS SEC542: Web App Penetration Testing and Ethical Hacking |
| Exam Registration: | GIAC Certification Registration |
| Sample Questions: | GIAC GWEB Sample Questions |
| Exam Way: | Online proctored or testing center-based exam |
| Pre Condition: | No formal prerequisite required, but basic web application and security knowledge is strongly recommended. |
| Official Syllabus URL: | https://www.giac.org/certifications/web-application-defender-gweb/ |
GIAC GWEB Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Secure Web Application Design | - Secure coding practices - Input validation and output encoding - Least privilege and access control design |
| Browser and Client-Side Security | - Content Security Policy (CSP) - Security headers and browser protections - Same-Origin Policy (SOP) |
| Web Application Architecture & Fundamentals | - Client-server model and web components - Web application lifecycle basics - HTTP/HTTPS protocol behavior |
| Web Application Defense and Mitigation | - Web application firewalls (WAF) - Logging and monitoring strategies - Incident detection and response basics |
| Authentication and Session Management | - Session tokens and cookie security - Multi-factor authentication concepts - Password storage and hashing mechanisms |
| Web Application Vulnerabilities | - Injection attacks (SQL, command, LDAP) - Cross-Site Scripting (XSS) - Cross-Site Request Forgery (CSRF) - Insecure direct object references (IDOR) |
GIAC Certified Web Application Defender Sample Questions:
Question 1
What role does a Web Application Firewall (WAF) play in modern web application security?
Response:
A. Provides a physical barrier between the web server and the internet
B. Acts as a reverse proxy to intercept and analyze HTTP/S traffic
C. Serves as the primary authentication mechanism
D. Encrypts data transmitted between the client and the server
Question 2
Which of the following mechanisms helps protect session tokens from being stolen?
Response:
A. Disabling token encryption
B. Using HTTP-only and Secure flags for cookies
C. Storing session tokens in local storage
D. Allowing session tokens in URL parameters
Question 3
Which of the following practices enhance AJAX application security?
(Choose two)
Response:
A. Allowing cross-site scripting (XSS) to enhance functionality
B. Using POST requests for sensitive data operations
C. Encrypting AJAX requests and responses
D. Implementing secure tokens for session management
Question 4
Which of the following is an advanced technology used for securing web applications against XSS attacks?
Response:
A. File Transfer Protocol (FTP) security
B. Browser Content Security Policy (CSP)
C. Virtual Private Network (VPN)
D. Secure/Multipurpose Internet Mail Extensions (S/MIME)
Question 5
What is the importance of automated security scanning in Continuous Integration/Continuous Deployment (CI/CD) pipelines?
Response:
A. It allows developers to deploy applications without manual review
B. It replaces the need for manual security testing
C. It ensures that the code is free from syntax errors
D. It identifies and helps remediate security vulnerabilities early in the development process
Solutions:
| Question 1 Answer: B | Question 2 Answer: B | Question 3 Answer: C,D | Question 4 Answer: B | Question 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Xavier

