GIAC GWAPT 試験概要:
| 認定ベンダー: | GIAC |
|---|---|
| 試験名: | GIAC Web Application Penetration Tester |
| 試験番号: | GWAPT |
| 認定の有効期間: | 4年 |
| 試験形式: | 多肢選択式, CyberLive ハンズオンラボ |
| 合格点: | 71% |
| 受験料: | $999 USD |
| 関連資格: | GIAC Penetration Tester (GPEN) GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) |
| 出題数: | 82 |
| 対応言語: | English |
| 試験時間: | 180 分 |
| サンプル問題: | GIAC GWAPT サンプル問題 |
| 受験方法: | ProctorUを通じたオンラインプロクター試験、またはPearson VUEを通じたテストセンターでの受験。 |
| 前提条件: | 正式な前提条件はありませんが、Webテクノロジー、ペネトレーションテスト、およびセキュリティの基礎知識を強く推奨します。 |
| 公式シラバスのURL: | https://www.giac.org/certification/web-application-penetration-tester-gwapt |
GIAC GWAPT 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: 認証攻撃と設定テスト | - 設定評価
|
| トピック 2: リコナイサンスとマッピング | - アプリケーション列挙
|
| トピック 3: セッション管理とSQLインジェクション | - テストツール
|
| トピック 4: Webアプリケーション概要 | - Webテクノロジーとアーキテクチャ
|
| トピック 5: クロスサイト攻撃とクライアントインジェクション | - クロスサイトリクエストフォージェリ
|
GIAC Web Application Penetration Tester GWAPT 認定 GWAPT 試験問題:
問題 #1
Which technique is commonly used to identify active services running on a web server?
A. Port scanning
B. Brute-forcing login credentials
C. Creating phishing emails
D. Exploiting stored XSS vulnerabilities
問題 #2
Which mechanisms can help prevent brute-force attacks on login pages? (Choose two)
A. Enforcing account lockout policies
B. Storing passwords in plaintext
C. Disabling HTTPS
D. Implementing CAPTCHAs
問題 #3
What are key signs that an application might be vulnerable to SQL injection? (Choose two)
A. Detailed error messages from the database
B. Encryption of sensitive data
C. Allowing input directly into SQL statements
D. Use of parameterized queries
問題 #4
Which testing methods are supported by fuzzing tools? (Choose two)
A. Brute force attacks
B. Validating secure encryption algorithms
C. Input randomization
D. Identifying buffer overflow vulnerabilities
問題 #5
A web application you are testing uses anti-CSRF tokens but allows GET requests for sensitive operations. How would you verify if it is still vulnerable to CSRF?
A. Embed a malicious request in an image tag and load it in the browser
B. Disable JavaScript in the browser and navigate the application
C. Attempt to change user data using a POST request
D. Reboot the server to reset sessions
解説:
| 問題 #1 正解: A | 問題 #2 正解: A、D | 問題 #3 正解: A、C | 問題 #4 正解: C、D | 問題 #5 正解: A |














1181 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
