GIAC GWEB Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Certified Web Application Defender |
| Exam Number: | GWEB |
| Real Exam Qty: | 75 |
| Related Certifications: | GIAC Web Application Penetration Tester (GWAPT) GIAC Certified Application Security Engineer (GCASE) |
| Exam Price: | $999 USD |
| Exam Format: | Multiple choice, Proctored |
| Certificate Validity Period: | 4 years |
| Available Languages: | English |
| Passing Score: | 68% |
| Exam Duration: | 180 minutes |
| Recommended Training: | SANS SEC522: Application Security: Securing Web Applications, APIs, and Microservices |
| Exam Registration: | PearsonVUE Scheduling GIAC Official Registration |
| Sample Questions: | GIAC GWEB Sample Questions |
| Exam Way: | Web-based proctored exam; remote via ProctorU or onsite at PearsonVUE centers |
| Pre Condition: | No formal prerequisites; basic understanding of web technologies recommended |
| Official Syllabus URL: | https://www.giac.org/certifications/certified-web-application-defender-gweb |
GIAC GWEB Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Proactive Defense, File Upload Security, and Response Readiness | 6% | - Anti-automation and defense-in-depth - File upload vulnerabilities and controls - Logging, monitoring, and incident response |
| Comprehensive Security Testing | 5% | - Vulnerability detection and remediation - Testing methodologies and tools |
| AJAX Technologies and Security Strategies | 3% | - AJAX architecture and risks - Secure implementation practices |
| Input Validation and Prevention of Input-Related Flaws | 15% | - Input validation and encoding techniques - HTTP response splitting and other input attacks - SQL injection, XSS, and command injection |
| Session Security and Business Logic Integrity | 10% | - Session management and token security - Cookie security attributes - Business logic flaws and protection |
| Cross-Origin Policy Attacks and Mitigation | 5% | - CORS misconfigurations - Same-origin policy concepts - CSRF attacks and defenses |
| Authentication Mechanisms and Best Practices | 12% | - Implementation and testing strategies - Single sign-on and third-party authentication - Authentication methods and weaknesses |
| Leading Edge Technologies and Web Security | 5% | - Emerging threats and technologies - Browser security and new standards |
| Access Control and Authorization Strategies | 12% | - Authorization enforcement - Access control models and flaws - Privilege escalation prevention |
| Modern Application Framework Issues and Serialization | 6% | - REST API and microservices security - Framework-specific security risks - Serialization and deserialization flaws |
| Web Application and HTTP Basics | 10% | - HTTP protocol fundamentals - Web application components and interactions - Common attack trends and vectors |
| Encryption and Protecting Sensitive Data | 8% | - Cryptography in transit and at rest - Data protection and tokenization - Secure storage and transmission practices |
| Web Services Security | 3% | - SOAP, XML, and WSDL security - Web service attacks and mitigation |
| Web Architecture and Configuration Security | 10% | - Server and service hardening - Configuration vulnerabilities and mitigation - Architecture design principles |
GIAC Certified Web Application Defender Sample Questions:
Question 1
Which web technology commonly uses serialization to transfer data between client and server?
Response:
A. WebSockets
B. XML
C. JSON
D. REST APIs
Question 2
In the context of high-level attack trends on web applications, what is a 'zero-day' exploit?
Response:
A. An attack that targets web applications with zero downtime or maintenance windows.
B. An attack that is launched on the same day a vulnerability is discovered in the software.
C. An attack that exploits a previously unknown hardware flaw.
D. An attack that exploits a security vulnerability on the same day it is patched by the software vendor.
Question 3
What is the primary goal of implementing anti-automation controls in a web application?
Response:
A. To allow unrestricted access to all site resources
B. To increase the application's response time
C. To enhance the user experience by reducing server load
D. To prevent bulk data extraction from the site
Question 4
Which of the following are common techniques used in web application security testing?
(Choose two)
Response:
A. Using deprecated encryption algorithms
B. Fuzzing to identify input vulnerabilities
C. Code injection to discover vulnerabilities
D. Disabling server logs during testing
Question 5
Which of the following are recommended practices for securing user authentication in web applications?
(Choose two)
Response:
A. Using hardcoded credentials in the codebase
B. Storing passwords in plaintext
C. Using multi-factor authentication (MFA)
D. Implementing password complexity requirements
Solutions:
| Question 1 Answer: C | Question 2 Answer: B | Question 3 Answer: D | Question 4 Answer: A,B | Question 5 Answer: C,D |

We're so confident of our products that we provide no hassle product exchange.


By Arlene


