GSEC · domain
Web Communication Security
This GSEC domain covers securing data in transit and the web application layer: TLS/SSL configuration, HTTP headers, cookies, and common web attacks like XSS, SQL injection, and CSRF. Questions are scenario-based, asking you to interpret logs, headers, or handshake details and identify the weakness, attack type, or correct mitigation.
Focused practice
Practice Web Communication Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Web Communication Security
You must be able to inspect TLS configurations, HTTP headers, and tokens to identify misconfigurations and attacks, then select the correct mitigation. The single most important thing is verifying that security controls actually enforce protection, such as rejecting 'none' JWT algorithms and avoiding weak cipher suites.
Analyzing TLS handshake cipher suites and identifying weaknesses such as CBC mode or RSA key exchange
Interpreting HTTP security headers like Content-Security-Policy, HSTS, and X-Frame-Options
Recognizing web attack patterns including XSS, SQL injection, CSRF, and session hijacking in logs
Evaluating JSON Web Token (JWT) configuration, including the 'none' algorithm vulnerability
Watch out for
Common Web Communication Security exam traps
- ▸Confusing reflected and stored XSS, or missing that 'unsafe-inline' in CSP weakens script-src protection against injection.
- ▸Assuming TLS_RSA_WITH_AES_128_CBC_SHA is secure; it lacks forward secrecy and uses CBC mode, which is vulnerable to padding oracle attacks.
- ▸Treating JWT 'alg': 'none' as valid or ignoring that the server must reject unsigned tokens and enforce a fixed algorithm.
Question index
All Web Communication Security questions (12)
Click any question to see the full explanation, or start a practice session above.
A security analyst is examining a web application that uses HTTP Strict Transport Security (HSTS). The analyst notices that the HSTS header is only sent on HTTPS responses and includes the 'preload' directive. Which additional measure must be taken to ensure the domain is included in browser preload lists?
Hard2A security engineer is configuring a web server to enforce secure communication and prevent man-in-the-middle attacks. The engineer wants to implement HTTP Strict Transport Security (HSTS) and ensure that it is properly deployed. Which TWO of the following are required for HSTS to be effective? (Choose two.)
Medium3A developer wants to prevent sensitive cookies from being transmitted over unencrypted HTTP connections. Which cookie attribute is specifically designed to enforce this requirement?
Hard4A security analyst is reviewing a web application that allows users to upload profile pictures. The application accepts files with .jpg and .png extensions, but the analyst discovers that an attacker can upload a file named 'avatar.php.jpg' and then access it directly via a URL. The server executes the file as PHP. Which security control would most directly prevent this type of attack?
Medium5An administrator observes that internal users are receiving certificate warnings when accessing a new internal web application. The organization uses an internal Certificate Authority (CA). What is the primary cause of this behavior?
Medium6During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?
Easy7A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query parameters. The requests appear to be attempting to inject SQL commands. Which of the following is the most effective mitigation to prevent SQL injection in this scenario?
Easy8A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA during the handshake. Which security weakness does this cipher suite selection introduce?
Medium9A security analyst is reviewing a web application's HTTP response headers and notices the following header: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'. The analyst is concerned about the application's resilience to cross-site scripting (XSS). Which of the following best describes the security implication of this policy?
Hard10A security analyst is examining a web application that uses JSON Web Tokens (JWT) for authentication. The analyst captures a token and notices that the header contains "alg": "none". The analyst is concerned about the security of the application. Which of the following best describes the risk associated with this token?
Hard11A web developer is implementing a new session management system and wants to ensure that session cookies are not accessible via JavaScript to mitigate cross-site scripting (XSS) attacks. Which cookie attribute should be set?
Easy12Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Web Communication Security domain cover on the GSEC exam?
- You must be able to inspect TLS configurations, HTTP headers, and tokens to identify misconfigurations and attacks, then select the correct mitigation. The single most important thing is verifying that security controls actually enforce protection, such as rejecting 'none' JWT algorithms and avoiding weak cipher suites.
- How many questions are in this domain?
- This page lists all 12 Web Communication Security questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Web Communication Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.