You must be able to inspect TLS configurations, HTTP headers, and tokens to identify misconfigurations and attacks, then select the correct mitigation. The single most important thing is verifying that security controls actually enforce protection, such as rejecting 'none' JWT algorithms and avoiding weak cipher suites.
Start practicing
Web Communication Security — choose a session length
Free · No account required
Domain overview
This GSEC domain covers securing data in transit and the web application layer: TLS/SSL configuration, HTTP headers, cookies, and common web attacks like XSS, SQL injection, and CSRF. Questions are scenario-based, asking you to interpret logs, headers, or handshake details and identify the weakness, attack type, or correct mitigation.
Exam objectives
Analyzing TLS handshake cipher suites and identifying weaknesses such as CBC mode or RSA key exchange
Interpreting HTTP security headers like Content-Security-Policy, HSTS, and X-Frame-Options
Recognizing web attack patterns including XSS, SQL injection, CSRF, and session hijacking in logs
Evaluating JSON Web Token (JWT) configuration, including the 'none' algorithm vulnerability
Confusing reflected and stored XSS, or missing that 'unsafe-inline' in CSP weakens script-src protection against injection.
Assuming TLS_RSA_WITH_AES_128_CBC_SHA is secure; it lacks forward secrecy and uses CBC mode, which is vulnerable to padding oracle attacks.
Treating JWT 'alg': 'none' as valid or ignoring that the server must reject unsigned tokens and enforce a fixed algorithm.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator observes that internal users are receiving certificate warnings when accessing a new internal web application. The organization uses an internal Certificate Authority (CA). What is the primary cause of this behavior?
2A developer wants to prevent sensitive cookies from being transmitted over unencrypted HTTP connections. Which cookie attribute is specifically designed to enforce this requirement?
3Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?
4During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?
5A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA during the handshake. Which security weakness does this cipher suite selection introduce?
6A security analyst is examining a web application that uses HTTP Strict Transport Security (HSTS). The analyst notices that the HSTS header is only sent on HTTPS responses and includes the 'preload' directive. Which additional measure must be taken to ensure the domain is included in browser preload lists?
7A security analyst is reviewing a web application that allows users to upload profile pictures. The application accepts files with .jpg and .png extensions, but the analyst discovers that an attacker can upload a file named 'avatar.php.jpg' and then access it directly via a URL. The server executes the file as PHP. Which security control would most directly prevent this type of attack?
8A web developer is implementing a new session management system and wants to ensure that session cookies are not accessible via JavaScript to mitigate cross-site scripting (XSS) attacks. Which cookie attribute should be set?
9A security analyst is reviewing a web application's HTTP response headers and notices the following header: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'. The analyst is concerned about the application's resilience to cross-site scripting (XSS). Which of the following best describes the security implication of this policy?
10A security engineer is configuring a web server to enforce secure communication and prevent man-in-the-middle attacks. The engineer wants to implement HTTP Strict Transport Security (HSTS) and ensure that it is properly deployed. Which TWO of the following are required for HSTS to be effective? (Choose two.)
11A security analyst is examining a web application that uses JSON Web Tokens (JWT) for authentication. The analyst captures a token and notices that the header contains "alg": "none". The analyst is concerned about the security of the application. Which of the following best describes the risk associated with this token?
12A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query parameters. The requests appear to be attempting to inject SQL commands. Which of the following is the most effective mitigation to prevent SQL injection in this scenario?
You must be able to inspect TLS configurations, HTTP headers, and tokens to identify misconfigurations and attacks, then select the correct mitigation. The single most important thing is verifying that security controls actually enforce protection, such as rejecting 'none' JWT algorithms and avoiding weak cipher suites.
The Courseiva GSEC question bank contains 12 questions in the Web Communication Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Web Communication Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included