GIAC GWAPT Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Web Application Penetration Tester Exam |
| Exam Number: | GWAPT |
| Exam Price: | $2,499 USD |
| Certificate Validity Period: | 4 years |
| Real Exam Qty: | 82 - 115 |
| Exam Format: | Hands-on practical (CyberLive), Multiple choice, Scenario-based |
| Related Certifications: | GIAC Penetration Tester (GPEN) GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) |
| Available Languages: | English |
| Passing Score: | 71% |
| Exam Duration: | 180 minutes |
| Recommended Training: | SANS SEC542: Web App Penetration Testing and Ethical Hacking |
| Exam Registration: | GIAC Official Registration Pearson VUE Testing Centers |
| Sample Questions: | GIAC GWAPT Sample Questions |
| Exam Way: | Online remote proctored (ProctorU) or onsite at Pearson VUE test centers; web-based, closed-book |
| Pre Condition: | No mandatory prerequisites; relevant work experience or completion of SANS SEC542 training highly recommended |
| Official Syllabus URL: | https://www.giac.org/certifications/web-application-penetration-tester-gwapt |
GIAC GWAPT Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Cross-Site Attacks and Client-Side Vulnerabilities | 15% | - Cross-Site Request Forgery (CSRF) - Cross-Site Scripting (XSS) - Client-side injection and manipulation |
| Topic 2: Web Application Authentication Attacks | 15% | - Multi-factor authentication flaws - Weak authentication mechanisms - User enumeration and bypass techniques |
| Topic 3: Web Application Overview | 10% | - Web application architecture and components - Web technologies and protocols (HTTP, HTTPS, AJAX) - Core security principles and vulnerabilities |
| Topic 4: Injection Attacks | 20% | - SQL injection - Command and code injection - XML External Entity (XXE) injection - Insecure deserialization |
| Topic 5: Web Application Testing Tools | - Proxies, scanners and exploitation frameworks - Manual testing and analysis tools | |
| Topic 6: Web Application Session Management | 15% | - Session token generation and handling - SSL/TLS and secure communication issues - Session hijacking and fixation |
| Topic 7: Reconnaissance and Mapping | 15% | - Discovery and enumeration techniques - Spidering and application mapping - Service and configuration identification |
| Topic 8: Web Application Configuration Testing | 10% | - Server and application misconfigurations - Access control and authorization flaws - Error handling and information disclosure |
GIAC Web Application Penetration Tester GWAPT Sample Questions:
Question 1
Which mechanisms can help prevent brute-force attacks on login pages? (Choose two)
A. Disabling HTTPS
B. Implementing CAPTCHAs
C. Enforcing account lockout policies
D. Storing passwords in plaintext
Question 2
What practices help secure web application authentication mechanisms? (Choose two)
A. Using CAPTCHA for login forms
B. Using salted password hashes
C. Enabling directory listing
D. Limiting session timeout durations
Question 3
Which of the following is an example of a client-side scripting language?
A. Python
B. Ruby
C. PHP
D. JavaScript
Question 4
Which reconnaissance techniques may expose directory structure vulnerabilities? (Choose two)
A. Secure cookie policies
B. User behavior analysis
C. Directory listing enabled on the server
D. Directory traversal attacks
Question 5
What is the purpose of the "Content-Security-Policy" HTTP header?
A. To restrict the sources of content that can be loaded by the browser
B. To allow cross-origin resource sharing
C. To enable directory browsing
D. To enforce client-side encryption
Solutions:
| Question 1 Answer: B,C | Question 2 Answer: A,B | Question 3 Answer: D | Question 4 Answer: C,D | Question 5 Answer: A |
We're so confident of our products that we provide no hassle product exchange.


By Barbara

