Courseiva

GSEC · topic practice

Web Communication Security practice questions

This GSEC domain covers securing data in transit and the web application layer: TLS/SSL configuration, HTTP headers, cookies, and common web attacks like XSS, SQL injection, and CSRF. Questions are scenario-based, asking you to interpret logs, headers, or handshake details and identify the weakness, attack type, or correct mitigation.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Web Communication Security

What the exam tests

What to know about Web Communication Security

You must be able to inspect TLS configurations, HTTP headers, and tokens to identify misconfigurations and attacks, then select the correct mitigation. The single most important thing is verifying that security controls actually enforce protection, such as rejecting 'none' JWT algorithms and avoiding weak cipher suites.

Analyzing TLS handshake cipher suites and identifying weaknesses such as CBC mode or RSA key exchange

Interpreting HTTP security headers like Content-Security-Policy, HSTS, and X-Frame-Options

Recognizing web attack patterns including XSS, SQL injection, CSRF, and session hijacking in logs

Evaluating JSON Web Token (JWT) configuration, including the 'none' algorithm vulnerability

Watch out for

Common Web Communication Security exam traps

  • ▸Confusing reflected and stored XSS, or missing that 'unsafe-inline' in CSP weakens script-src protection against injection.
  • ▸Assuming TLS_RSA_WITH_AES_128_CBC_SHA is secure; it lacks forward secrecy and uses CBC mode, which is vulnerable to padding oracle attacks.
  • ▸Treating JWT 'alg': 'none' as valid or ignoring that the server must reject unsigned tokens and enforce a fixed algorithm.

Practice set

Web Communication Security questions

20 questions · select your answer, then reveal the explanation

An analyst is investigating a web application that frequently transmits sensitive session tokens over plain HTTP during initial login redirection before switching to HTTPS. Which vulnerability class does this pattern represent, and how should it be remediated?

A security engineer notices that a web application reflects user-supplied input directly inside a JavaScript execution context within a script block without proper encoding. Which remediation strategy provides the most effective defense-in-depth against resulting XSS attacks?

A security architect is designing a secure API authentication workflow using JSON Web Tokens. Which THREE implementation practices are critical to ensure token integrity and prevent signature verification bypasses?

Which TWO of the following headers are critical for preventing Clickjacking and Cross-Site Scripting (XSS) in modern web applications? (Choose two)

A security engineer is reviewing a web application's login flow. The application uses a session cookie that is set with the Secure attribute, but the engineer notices that the cookie is still being sent over an unencrypted HTTP connection during the initial login request. Which of the following is the most likely explanation for this behavior?

A security engineer is configuring a web server to mitigate Cross-Site Request Forgery (CSRF) attacks. The application uses session cookies for authentication. Which of the following implementations provides the strongest protection against CSRF while maintaining usability?

A security engineer is configuring TLS for a web application. The organization requires that all connections use forward secrecy to protect past session keys if the server's private key is compromised. Which of the following cipher suites should be selected to meet this requirement?

A GSEC analyst is reviewing a web application that sets session cookies with the Secure and HttpOnly attributes. The analyst observes that an attacker on the same local network can still capture the session cookie when a user visits the site over an unencrypted HTTP URL that redirects to HTTPS. Which mechanism should the organization implement to prevent the cookie from ever being transmitted over cleartext HTTP?

An administrator observes that internal users are receiving certificate warnings when accessing a new internal web application. The organization uses an internal Certificate Authority (CA). What is the primary cause of this behavior?

A developer wants to prevent sensitive cookies from being transmitted over unencrypted HTTP connections. Which cookie attribute is specifically designed to enforce this requirement?

Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?

Exhibit

HTTP/1.1 200 OK
Set-Cookie: session_id=12345; HttpOnly; Secure
Content-Type: text/html

During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?

A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA during the handshake. Which security weakness does this cipher suite selection introduce?

A security analyst is examining a web application that uses HTTP Strict Transport Security (HSTS). The analyst notices that the HSTS header is only sent on HTTPS responses and includes the 'preload' directive. Which additional measure must be taken to ensure the domain is included in browser preload lists?

A security analyst is reviewing a web application that allows users to upload profile pictures. The application accepts files with .jpg and .png extensions, but the analyst discovers that an attacker can upload a file named 'avatar.php.jpg' and then access it directly via a URL. The server executes the file as PHP. Which security control would most directly prevent this type of attack?

A web developer is implementing a new session management system and wants to ensure that session cookies are not accessible via JavaScript to mitigate cross-site scripting (XSS) attacks. Which cookie attribute should be set?

A security analyst is reviewing a web application's HTTP response headers and notices the following header: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'. The analyst is concerned about the application's resilience to cross-site scripting (XSS). Which of the following best describes the security implication of this policy?

A security engineer is configuring a web server to enforce secure communication and prevent man-in-the-middle attacks. The engineer wants to implement HTTP Strict Transport Security (HSTS) and ensure that it is properly deployed. Which TWO of the following are required for HSTS to be effective? (Choose two.)

A security analyst is examining a web application that uses JSON Web Tokens (JWT) for authentication. The analyst captures a token and notices that the header contains "alg": "none". The analyst is concerned about the security of the application. Which of the following best describes the risk associated with this token?

A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query parameters. The requests appear to be attempting to inject SQL commands. Which of the following is the most effective mitigation to prevent SQL injection in this scenario?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Web Communication Security sessions

Start a Web Communication Security only practice session

Every question in these sessions is drawn from the Web Communication Security domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Web Communication Security?
You must be able to inspect TLS configurations, HTTP headers, and tokens to identify misconfigurations and attacks, then select the correct mitigation. The single most important thing is verifying that security controls actually enforce protection, such as rejecting 'none' JWT algorithms and avoiding weak cipher suites.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Web Communication Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Web Communication Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.