Updated GIAC GWEB Dumps – Check Free GWEB Exam Dumps (2025) [Q84-Q100]

Share

Updated GIAC GWEB Dumps – Check Free GWEB Exam Dumps (2025)

Updated GWEB exam with GIAC Real Exam Questions

NEW QUESTION # 84
What tool is commonly used for automated web application security testing?
Response:

  • A. Burp Suite
  • B. Docker
  • C. Terraform
  • D. Wireshark

Answer: A


NEW QUESTION # 85
What are common practices for preventing cross-origin attacks in web applications?
(Choose two)
Response:

  • A. Allowing all domains in CORS configuration
  • B. Allowing cross-origin access without authentication
  • C. Using SameSite cookies
  • D. Applying strict validation on cross-origin requests

Answer: C,D


NEW QUESTION # 86
What role does file content validation play in securing file upload features?
Response:

  • A. It enhances the visual consistency of user-uploaded files.
  • B. It increases the speed of file transfer to the server.
  • C. It prevents the upload of files that could execute malicious code.
  • D. It ensures that files are compatible with the application's features.

Answer: C


NEW QUESTION # 87
Which of the following is considered a secure practice in web authentication?
Response:

  • A. Using the same passwords across multiple systems for convenience
  • B. Implementing two-factor authentication
  • C. Using plain text storage for passwords
  • D. Relying solely on security questions for user authentication

Answer: B


NEW QUESTION # 88
For effective mitigation of cross-origin policy attacks, what should be implemented?
(Choose Three)
Response:

  • A. Implementing Content Security Policy (CSP)
  • B. Allowing all subdomains to share resources freely
  • C. Employing strict CORS policies
  • D. Using document.domain for cross-origin resource sharing
  • E. Validating and sanitizing all user input

Answer: A,D,E


NEW QUESTION # 89
What are common techniques to prevent input-related vulnerabilities in web applications?
(Choose two)
Response:

  • A. Allowing arbitrary input into SQL queries
  • B. Disabling input validation for specific users
  • C. Validating input length, type, and format
  • D. Implementing output encoding for all user input

Answer: C,D


NEW QUESTION # 90
Which of the following is an effective mitigation technique against CSRF attacks?
Response:

  • A. Disabling cookies in the user's browser
  • B. Using GET requests for state-changing operations
  • C. Using the same-origin policy with no exceptions
  • D. Including a unique token in every POST request

Answer: D


NEW QUESTION # 91
Which HTTP header is crucial for preventing unauthorized cross-origin requests in a web application?
Response:

  • A. X-XSS-Protection
  • B. Content-Security-Policy
  • C. Access-Control-Allow-Origin
  • D. X-Frame-Options

Answer: C


NEW QUESTION # 92
Which of the following security practices are essential when securing RESTful web services?
(Choose two)
Response:

  • A. Using GET requests for all data manipulation
  • B. Using HTTPS for all communication
  • C. Allowing unsecured connections for faster performance
  • D. Implementing input validation for all request parameters

Answer: B,D


NEW QUESTION # 93
What are common security challenges when working with modern web technologies?
(Choose two)
Response:

  • A. Ensuring secure communication in WebRTC
  • B. Avoiding strong encryption algorithms
  • C. Using deprecated HTTP/1.1 methods
  • D. Properly securing WebSocket connections

Answer: A,D


NEW QUESTION # 94
What is the primary goal of implementing anti-automation controls in a web application?
Response:

  • A. To allow unrestricted access to all site resources
  • B. To prevent bulk data extraction from the site
  • C. To enhance the user experience by reducing server load
  • D. To increase the application's response time

Answer: B


NEW QUESTION # 95
Which of the following best practices should be used to protect sensitive data in a web application?
(Choose two)
Response:

  • A. Encrypting sensitive data using strong encryption algorithms like AES
  • B. Using outdated hashing algorithms for securing data
  • C. Using tokenization for sensitive data such as credit card numbers
  • D. Storing passwords in plaintext

Answer: A,C


NEW QUESTION # 96
Which of the following are considered best practices in securing APIs for web applications?
(Choose Two)
Response:

  • A. Encrypting API payloads using proprietary algorithms
  • B. Implementing rate limiting
  • C. Using API keys as the sole authentication method
  • D. Validating and sanitizing all inputs

Answer: B,D


NEW QUESTION # 97
Which two practices should be included in a web application's incident response plan?
(Choose Two)
Response:

  • A. Defined procedures for classifying the severity of incidents
  • B. Regular public disclosure of all detected security incidents
  • C. Immediate system shutdown upon detecting an incident
  • D. Communication plan for stakeholders

Answer: A,D


NEW QUESTION # 98
When dealing with serialization, which two of the following are crucial security considerations?
(Choose Two)
Response:

  • A. Avoiding the exposure of sensitive data during the serialization process
  • B. Validating serialized objects before deserializing them
  • C. Ensuring that data is serialized in a compact format
  • D. Using only native serialization formats for security

Answer: A,B


NEW QUESTION # 99
Which of the following practices enhance AJAX application security?
(Choose two)
Response:

  • A. Allowing cross-site scripting (XSS) to enhance functionality
  • B. Encrypting AJAX requests and responses
  • C. Using POST requests for sensitive data operations
  • D. Implementing secure tokens for session management

Answer: B,D


NEW QUESTION # 100
......

Actual GWEB Exam Recently Updated Questions with Free Demo: https://www.dumps4pdf.com/GWEB-valid-braindumps.html