最新的GIAC Certified Web Application Defender - GWEB免費考試真題
問題1
Which of the following is the best approach to validate user input?
Response:
Response:
正確答案: C
問題2
In the context of file uploads, what are two critical security checks to implement?
(Choose Two)
Response:
(Choose Two)
Response:
正確答案: A,C
問題3
What is the primary defense mechanism against Cross-Site Scripting (XSS) attacks?
Response:
Response:
正確答案: C
問題4
In the context of web services, what is the primary security concern with improperly secured WSDL files?
Response:
Response:
正確答案: D
問題5
What is the primary goal of implementing anti-automation controls in a web application?
Response:
Response:
正確答案: D
問題6
Which of the following is an effective mitigation technique against CSRF attacks?
Response:
Response:
正確答案: B
問題7
What is the role of session timeout in session security?
Response:
Response:
正確答案: B
問題8
What measures can be implemented to prevent CSRF attacks in web applications?
(Choose two)
Response:
(Choose two)
Response:
正確答案: A,C
問題9
What best practice should be followed when developing secure RESTful APIs?
Response:
Response:
正確答案: B
問題10
Which encryption algorithm is recommended for securing sensitive data at rest?
Response:
Response:
正確答案: B
問題11
What is a significant risk when using third-party authentication services?
Response:
Response:
正確答案: D
問題12
What is a fundamental aspect of securing a web application that employs various modern application frameworks?
Response:
Response:
正確答案: D
問題13
Which of the following security practices are essential when securing RESTful web services?
(Choose two)
Response:
(Choose two)
Response:
正確答案: C,D
問題14
In the context of access control, which of the following attack techniques primarily involves gaining unauthorized access to systems by exploiting flaws in their authentication or authorization mechanisms?
Response:
Response:
正確答案: D
問題15
Which two of the following are important considerations when implementing SSL/TLS for protecting data in transit?
(Choose Two)
Response:
(Choose Two)
Response:
正確答案: B,C

