Last week I cleared the GWEB exam, and a lot of people asked me how I prepared. So here is my breakdown of how I studied for it and what worked for me. This is actually the second GIAC exam I cleared using the same approach, the first being the GWAPT (GIAC Web Application Penetration Tester), so I have a fair bit of confidence in the method by now.
Note: If you’re short on time, skip to the “What I’d Tell Someone Starting Out” section at the bottom for the quick takeaways.
What is the GIAC Web Application Defender (GWEB) Certification
It’s a practitioner-level certification by GIAC, the credentialing arm of SANS Institute. This exam tests your ability to identify and defend against the most common web application vulnerabilities: SQL injection, XSS, broken authentication, session attacks, CSRF, and a lot more. You can find more information about this exam here.
It’s tied to the SANS SEC522 course (Application Security: Securing Web Apps, APIs, and Microservices) and is genuinely hands-on in its expectations. Certainly not a memorization test. If you are interested in the training, you can find more details about the course here.
Who should take this certification?
Straight from GIAC, this cert is aimed at application developers, security analysts, application architects, pen testers who want to understand defensive strategies, and auditors at PCI-compliant organizations. But honestly, if you work anywhere near web applications in a security capacity, this is relevant to you.
For anyone wondering why I took this course, I’ve been working in application security for a while and already had solid footing in this space. The reason I pursued GWEB was to formalize that knowledge, pressure-test it against a rigorous syllabus, and have a recognized credential that reflects it.
Are certs worth it in the age of AI?
Honestly, I get why people ask this. AI can do a lot now, and it’s tempting to think structured learning and certifications are becoming less relevant. But I’d argue the opposite. AI accelerates you; it doesn’t replace understanding. And in security especially, if you don’t have the foundational knowledge, you won’t catch it when AI gets something wrong, oversimplifies, or produces something that looks correct but isn’t. You need to know enough to question it. That’s what certs, and the studying that comes with them, actually build.
Exam Format
It’s 75 questions, 3 hours, with a passing score of 68%. The exam is proctored and open-book. That last part sounds reassuring, but don’t let it make you complacent. With 75 questions in 3 hours, you have roughly 2 minutes per question. If you’re hunting for basic concepts during the exam, you’re going to run out of time.
What You’ll Learn
What I liked about this course is that it doesn’t just teach you how to defend. It covers both sides. You understand how attacks work and then how to stop them. The syllabus spans web application architecture, HTTP fundamentals, authentication and session management, access control, the usual attack categories such as injection, XSS, and CSRF, encryption, API security, AJAX and web services, DevSecOps, and more.
How IÂ Studied
Full disclosure: I went very slow initially. The books sat around longer than I’d like to admit; other things kept taking priority. So I can’t give you an accurate picture of the total time it took. What I can say is that the last 3 weeks before the exam is where most of the real prep happened. If you’re more disciplined than I was, you can probably do this more efficiently.
The Live Course Was a Mixed Bag
I started with the SANS live online training. It covers a lot of ground, and if you’ve been out of the habit of sitting through long training programs, it can feel like a lot to take in. I wouldn’t rely on it alone to get you exam-ready. That said, the labs between topics were genuinely fun. They broke up the monotony, and the hands-on exercises made the concepts engaging. Do every lab and take your time with them.
Read the Books Once, But With a System
The SANS materials span multiple books. I read through all of them once, but I didn’t just read passively. I did two things at the same time that made a real difference later.
First, I built an index in Excel. Each row had the page number, chapter, topic title, and a few keywords. By the end, I had a searchable master index of the entire curriculum.
Second, I added physical sticky notes to the books as I went. One sticky per major topic. I color-coded them by category so I could visually navigate the books quickly. Together, the digital index and the physical sticky notes saved me a huge amount of time on exam day.
Practice Exam 1, Then Deep Dive the Weak Spots
After finishing the books and building the index, I took the first GIAC practice test. It showed me exactly where my understanding was shaky. For those weak areas, I didn’t just reread the SANS pages. I went outside the material and watched videos, read blog posts, and worked through examples until I actually understood the concept rather than just recognizing it. That step takes time, but it’s where you go from borderline to confident.
A Quick Reread Before the Second Practice Test
Once I felt solid on the weak topics, I did a second faster read of the books. The goal here wasn’t to learn new things but to reinforce the mental map of where everything lives. Even with a great index, if you have no spatial sense of the material, the exam gets stressful. After the second read, I knew roughly which book and which part of that book each major topic sat in.
Practice Exam 2 the Day Before
I took the second practice test the day before my actual exam. By that point I was scoring well, which helped me go in feeling calm rather than anxious. If you still have gaps at this stage, don’t panic. Use the results to do a final targeted review that evening and then get some sleep.
What I’d Tell Someone Starting Out
Start building your index from day one. Don’t wait until you finish reading to go back and create it. You’ll save yourself a ton of time, and it’ll be richer if you build it as you go.
Take the labs seriously. They’re the closest thing to real experience that this course offers.
Don’t trust the open book to rescue you. The index and sticky notes are your tools for making open book actually useful under time pressure.
When you find a weak area, go beyond the SANS books. Videos and external resources help the foundational concepts land properly.
And review every wrong answer on the practice tests. Not just the ones you got wrong, but the ones you guessed on. The guesses are where your real gaps are hiding.
Good luck, and if you have questions about the exam or the study approach, drop them in the comments.
Disclaimer
The views and opinions expressed are those of the author and do not necessarily reflect the views of any affiliated organizations. All content is for informational purposes only.