VIP Exclusive
GWAPT GIAC Web Application Penetration Tester VIP Practice Exam
GWAPT — The GIAC Web Application Penetration Tester (GWAPT) certification is issued by GIAC (Global Information Assurance Certification), associated with the SANS SEC542 course; the real exam consists of 75 questions with a 2-hour time limit and a 71% passing score, covering web app recon, injection attacks, authentication flaws, session management, client-side attacks, and API/web service testing.
30
Questions
120m
Time Limit
71.00%
To Pass
Question 1 of 30👑 VIP
During a black-box web application assessment, you navigate to the target and notice the response headers include: 'X-Powered-By: PHP/7.1.3' and 'Server: Apache/2.4.6 (CentOS)'. You also find a file at /robots.txt listing '/admin-console/', '/backup/', and '/api/internal/'. Which of the following best describes how you should proceed with this information during the reconnaissance phase?
Questions 2–30 and full explanations are VIP-exclusive.