GIAC GWEB 考試概覽:
| 認證廠商: | GIAC (SANS Institute) |
|---|---|
| 考試名稱: | GIAC 認證網頁應用程式防禦專家 (GWEB) 認證考試 |
| 考試代碼: | GWEB |
| 考試時間: | 240 分鐘 |
| 及格分數: | 約 73% |
| 證照有效期限: | 4 年 |
| 考試形式: | 選擇題, 線上或現場監考考試 |
| 支援語言: | English |
| 實際考試題數: | 約 106 題 |
| 考試費用: | $949 USD (標準 GIAC 考試費用;可能因地區/方案而異) |
| 相關認證: | GIAC 安全軟體程式設計師 (GSSP) GIAC 網頁應用程式滲透測試專家 (GWAPT) |
| 推薦課程: | SANS SEC542: 網頁應用程式滲透測試與道德駭客 |
| 考試報名: | GIAC 認證註冊 |
| 範例考題: | GIAC GWEB 範例考題 |
| 考試方式: | 線上監考或考試中心實體考試 |
| 必備條件: | 無強制先決條件,但強烈建議具備基礎網頁應用程式與資訊安全知識。 |
| 官方大綱網址: | https://www.giac.org/certifications/web-application-defender-gweb/ |
GIAC GWEB 考試大綱主題:
| 章節 | 目標 |
|---|---|
| 主題 1: 網頁應用程式防禦與緩解 | - 記錄與監控策略 - 事件偵測與回應基礎 - 網頁應用程式防火牆 (WAF) |
| 主題 2: 身分驗證與會話管理 | - 會話權杖與 Cookie 安全性 - 密碼儲存與雜湊機制 - 多因素驗證概念 |
| 主題 3: 網頁應用程式漏洞 | - 注入攻擊 (SQL, command, LDAP) - 跨網站請求偽造 (CSRF) - 跨網站指令碼 (XSS) - 不安全的直接物件參照 (IDOR) |
| 主題 4: 網頁應用程式架構與基礎 | - 用戶端-伺服器模型與網頁元件 - HTTP/HTTPS 協定行為 - 網頁應用程式生命週期基礎 |
| 主題 5: 安全網頁應用程式設計 | - 最小權限與存取控制設計 - 安全編碼實踐 - 輸入驗證與輸出編碼 |
| 主題 6: 瀏覽器與用戶端安全性 | - 安全標頭與瀏覽器防護 - 同源政策 (SOP) - 內容安全政策 (CSP) |
最新的 Cloud Security GWEB 免費考試真題:
問題 #1
What is the main purpose of using encryption in web applications?
Response:
A. To prevent denial-of-service (DoS) attacks
B. To decrease response times
C. To secure sensitive data both at rest and in transit
D. To improve application performance
問題 #2
When implementing encryption in a web application, which of the following practices should be followed?
(Choose Two)
Response:
A. Use a new key for every encryption operation
B. Use proven cryptographic libraries instead of creating your own
C. Regularly rotate encryption keys
D. Store encryption keys in the same database as the encrypted data
問題 #3
What is the role of 'SameSite' cookie attribute in preventing CSRF attacks?
Response:
A. It ensures cookies are only sent over HTTPS
B. It isolates cookies to specific domain paths to prevent unauthorized access
C. It prevents cookies from being sent in cross-site requests
D. It encrypts cookies to prevent interception and tampering
問題 #4
What is the primary function of two-factor authentication (2FA)?
Response:
A. To limit the number of login attempts
B. To provide an additional layer of security by requiring two forms of identity verification
C. To improve application speed
D. To block all failed login attempts
問題 #5
Which of the following best practices should be used to protect sensitive data in a web application?
(Choose two)
Response:
A. Storing passwords in plaintext
B. Encrypting sensitive data using strong encryption algorithms like AES
C. Using tokenization for sensitive data such as credit card numbers
D. Using outdated hashing algorithms for securing data
問題與答案:
| 問題 #1 答案: C | 問題 #2 答案: A,B | 問題 #3 答案: C | 問題 #4 答案: B | 問題 #5 答案: B,C |

下載最新試用版
1246位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








112.203.255.* -
我已经通過了 GWEB 考试拿到了证书。現在的我有一份很好的工作,是因為有 VCESoft 網站的幫助,谢谢!