TechNuggets Academy

Web Communication and Cloud Security

Free GIAC Security Essentials practice — 6 questions on Web Communication and Cloud Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Web Communication and Cloud Security
A penetration tester runs 'curl http://169.254.169.254/latest/meta-data/iam/security-credentials/' from a compromised web application server hosted on AWS EC2 and successfully retrieves temporary IAM credentials without any authentication header. The instance was launched with the default IMDS configuration prior to a recent security hardening pass. Which single change would BEST prevent this SSRF-to-credential-theft attack?
IMDSv2 requires a session token obtained via an HTTP PUT request with a custom header, which a typical SSRF vector (server-side GET request forgery) cannot forge, and setting the hop limit to 1 blocks requests proxied through containers or reverse proxies, closing the classic metadata-credential-theft path.
Question 2 of 6 · Web Communication and Cloud Security
During a TLS configuration review, an analyst finds a server offering the cipher suite TLS_RSA_WITH_AES_256_GCM_SHA384 as its top preference. A colleague argues this should be deprioritized in favor of TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. What is the SECURITY reason for this recommendation?
In RSA key-exchange cipher suites, the pre-master secret is encrypted directly with the server's static RSA public key; if that private key is later stolen, all previously captured traffic can be decrypted. ECDHE generates an ephemeral key pair per session, providing perfect forward secrecy so past sessions remain safe even after key compromise.
Question 3 of 6 · Web Communication and Cloud Security
A company's site is vulnerable to SSL-stripping attacks on public Wi-Fi because users often type 'example.com' without 'https://'. The security team wants browsers to automatically upgrade all future connections to HTTPS for this domain AND all of its subdomains, even on the very first visit, without relying on a redirect. Which configuration achieves this?
HSTS with includeSubDomains protects subdomains, a max-age of one year is the recommended durable policy, and preload submission bakes the enforcement directly into browser source code so protection applies even on a user's very first connection attempt, before any HSTS header could ever be received over an initial unencrypted request.
Question 4 of 6 · Web Communication and Cloud Security
A company migrates its custom-built order-processing application from on-premises servers to a cloud provider's Platform-as-a-Service (PaaS) application hosting offering (e.g., a managed app service tier). Under the shared responsibility model, which security task REMAINS the customer's responsibility?
In PaaS, the provider manages the underlying OS, hardware, physical facility, and the managed runtime, but the customer still owns everything they build on top of it — application code, business logic, authentication/authorization, session handling, and input validation remain squarely the customer's responsibility.
Question 5 of 6 · Web Communication and Cloud Security
A web application sets a session cookie with the attributes: Secure; HttpOnly; SameSite=Lax. A researcher demonstrates a cross-site request forgery attack still succeeds when a malicious third-party site auto-submits a hidden GET-based form that triggers a state-changing action (a fund transfer) on the target application. What is the MOST likely reason the SameSite=Lax attribute failed to prevent this?
SameSite=Lax is designed to allow cookies on 'safe' cross-site navigations, which includes top-level GET requests (like clicking a link or an auto-submitting GET form), specifically to preserve usability for things like following links from external sites. The real design flaw here is the application performing a state-changing action on a GET request; state changes should require POST with CSRF tokens and SameSite=Strict or Lax combined with proper method restrictions.
Question 6 of 6 · Web Communication and Cloud Security
A web application accepts user-supplied XML documents for a bulk-upload feature. An attacker submits a document containing a DOCTYPE declaration with a custom entity that references 'file:///etc/passwd', and the application's response includes the contents of that file. Which single remediation directly closes this vulnerability class at its root?
This is a classic XML External Entity (XXE) injection. The root cause is that the XML parser is configured to resolve external entities and process DTDs at all; disabling DTD processing and external entity resolution entirely (the recommended OWASP fix) eliminates the vulnerability class regardless of payload variation, rather than trying to filter specific malicious strings.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →