최신GIAC Web Application Penetration Tester GWAPT - GWAPT무료샘플문제
문제1
Which HTTP method is used to retrieve data from a server?
Which HTTP method is used to retrieve data from a server?
정답: A
문제2
Which mechanisms can help prevent brute-force attacks on login pages? (Choose two)
Which mechanisms can help prevent brute-force attacks on login pages? (Choose two)
정답: B,C
문제3
Which of the following tools is commonly used to identify misconfigurations in web applications?
Which of the following tools is commonly used to identify misconfigurations in web applications?
정답: C
문제4
Which features improve session security in web applications? (Choose two)
Which features improve session security in web applications? (Choose two)
정답: A,C
문제5
During a security assessment, you find that verbose error messages are enabled. What is the immediate action you should recommend?
During a security assessment, you find that verbose error messages are enabled. What is the immediate action you should recommend?
정답: C
문제6
What is a SQL injection attack?
What is a SQL injection attack?
정답: D
문제7
Which type of XSS attack involves injecting malicious code that gets stored on the server and executed on subsequent page loads?
Which type of XSS attack involves injecting malicious code that gets stored on the server and executed on subsequent page loads?
정답: A
문제8
What is the purpose of spidering during reconnaissance?
What is the purpose of spidering during reconnaissance?
정답: D
문제9
While spidering a web application, you notice an endpoint /debug/logs. How should you proceed?
While spidering a web application, you notice an endpoint /debug/logs. How should you proceed?
정답: A