Be able to read an API request, spot the modified identifier or query, and name the exact failed control (object-level authorization, not authentication). For GraphQL, identify missing depth or complexity limits as the cause of denial of service.
Start practicing
Web App API Attacks — choose a session length
Free · No account required
Domain overview
This GCIH domain covers attacks against web applications and APIs, including REST parameter tampering, IDOR, GraphQL abuse, and injection flaws. Questions test whether you can identify the failed security control, map the attack to the OWASP-style category, and choose the correct incident response action or documentation artifact.
Exam objectives
Identifying broken object level authorization (IDOR) when integer identifiers in REST paths or query parameters are modified
Recognizing GraphQL resource exhaustion from deeply nested or overly complex queries leading to denial of service
Selecting essential API security documentation components for incident responders, such as authentication schemes and endpoint inventories
Distinguishing authentication failures from authorization failures when a low-privileged user reaches administrative records
Labeling IDOR as broken authentication; the user is authenticated, so the failure is authorization or access control at the object level.
Assuming input validation fixes IDOR; the fix is server-side authorization checks per object, not sanitizing the identifier.
Treating GraphQL depth attacks as injection; they are resource exhaustion or lack of query cost limiting, not code injection.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?
2During a web application incident investigation, the SOC analyst discovers that an attacker sent a modified JSON payload containing an unexpected administrative attribute "is_admin": true during user registration, which successfully elevated the user's privileges. What vulnerability enabled this exploitation?
3An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /api/v1/user/details?id=124. This vulnerability indicates a failure in which security control?
4Which TWO methods are effective for mitigating Mass Assignment vulnerabilities in RESTful APIs?
5An API uses OAuth 2.0. An attacker sends a request with a modified 'redirect_uri' parameter to an authorization endpoint. If successful, this could lead to which type of vulnerability?
6Which THREE items are essential components of an API security documentation strategy for incident responders?
7When analyzing a JSON Web Token (JWT) for potential security weaknesses in an API, which scenario indicates a 'None' algorithm attack is possible?
8Which security measure is most effective against API-based Denial of Service (DoS) attacks targeted at resource-intensive endpoints?
9Refer to the exhibit. An attacker changes the 'final_price' to 0.00. What is the most likely vulnerability?
10Which of the following is the most significant security risk associated with the use of 'API Keys' for authentication in modern cloud-native environments?
11In the context of API security, what does the 'Broken Object Level Authorization' (BOLA) vulnerability typically involve?
12Which THREE actions are recommended to secure APIs against Server-Side Request Forgery (SSRF)?
13An incident responder is analyzing an API access log and notices a user with ID 104 is able to modify account settings for user ID 105 by simply changing the integer value in the URI endpoint from /api/v1/users/104/settings to /api/v1/users/105/settings without any additional token validation or role checks. Which specific OWASP API Security Top 10 vulnerability class does this scenario represent?
14An incident responder is investigating a modern web application and notices that users can modify object identifiers in REST API endpoints to access sensitive records belonging to other tenants. Which primary vulnerability category does this represent?
15An incident responder is investigating a RESTful API breach where an authenticated low-privileged user accessed administrative records by modifying an integer identifier in the resource path from /api/v1/users/104 to /api/v1/users/1. Which type of vulnerability has been exploited?
16During a penetration test of a GraphQL API, an incident handler finds that the introspection system is enabled and can be queried without authentication. The handler retrieves the full schema, including hidden fields and mutations. What is the most significant security impact of this finding?
17An incident responder is analyzing a web application that uses a REST API. The API accepts a 'file' parameter that specifies a URL from which to fetch an image. The responder observes that an attacker supplied a URL pointing to an internal metadata service (e.g., http://169.254.169.254/latest/meta-data/) and successfully retrieved sensitive instance credentials. Which vulnerability class does this represent?
18A GCIH incident handler is reviewing web server logs after a suspected API reconnaissance campaign. The logs show numerous requests to endpoints such as /api/v1/users, /api/v2/users, /api/v3/users, and /api/internal/users, all returning HTTP 404 except one. Which attack technique is most consistent with this pattern?
19A security analyst is reviewing logs from a web application firewall (WAF) and notices a series of requests containing payloads like ' OR 1=1 --' and 'UNION SELECT username, password FROM users'. These requests are targeting the login endpoint. Which type of attack is being attempted?
20During an incident response engagement, a GCIH analyst examines an API that accepts JSON input and notices that the application returns detailed database error messages when a single quote is inserted into the 'username' field. The analyst also observes that the same endpoint returns a 500 error when a specially crafted JSON object with nested arrays is submitted. Which vulnerability class is the analyst most likely investigating?
21An incident handler reviews web server logs from an e-commerce application and finds a burst of requests where the JSON body of a POST to /api/v2/orders/checkout contains a deeply nested object several thousand levels deep, causing the backend deserializer to exhaust CPU and memory until the worker crashes. The application accepts arbitrary JSON and binds it directly to internal model objects. Which vulnerability class best describes this attack?
22A GCIH incident responder is investigating a suspected API attack where an attacker manipulated a JSON Web Token (JWT) to gain unauthorized access. The responder needs to identify which two conditions would allow a JWT 'kid' (Key ID) header injection attack to succeed. (Choose two.)
23A GCIH analyst is called after a SaaS provider reports that an integration partner's API traffic began returning other tenants' records. The partner's client was calling /api/v3/documents/{documentId} and had recently started sending a second header, X-Tenant-Id, that the gateway trusts to route requests. The analyst confirms the partner is authenticated with a valid OAuth 2.0 bearer token scoped to its own tenant. Which weakness allowed the cross-tenant exposure?
24A GCIH analyst is examining a web application that uses GraphQL. The analyst notices that an attacker sent a deeply nested query that caused the server to consume excessive resources, leading to a denial of service. Which GraphQL-specific vulnerability is being exploited?
25A GCIH candidate is reviewing a REST API that accepts XML in an upload endpoint used for importing supplier catalogs. During a purple-team exercise, testers want to demonstrate how XML-specific parser weaknesses could be abused against this endpoint. Which two techniques should the testers attempt to validate the parser's defenses? (Choose two.)
26A SOC analyst triages an alert showing that a mobile banking API responded to a request for /api/accounts/8842/transactions with HTTP 200 and another customer's transaction list. The requesting user was authenticated normally with a valid session token, but the account number in the URL belonged to a different customer. The API returned data without checking whether the authenticated user owned that account. Which vulnerability does this represent?
27An incident responder is examining a GraphQL API after a breach report. Query logs show a single POST to /graphql containing a query that requests a user's profile, that user's friends, each friend's friends, and so on through deeply chained relationship fields, all in one request. The response was several megabytes and the database showed a spike in joins. No authentication bypass occurred. Which attack does this describe?
28During an incident involving a single-page application, a handler inspects a GraphQL endpoint at /graphql used for a customer portal. The handler captures a query that requests only the fields needed for a profile view, but the server response includes additional fields such as internalAccountTier, billingNotes, and ssnLastFour. The application uses a single shared GraphQL schema and no field-level authorization middleware. Which GraphQL-specific weakness is most directly demonstrated?
Be able to read an API request, spot the modified identifier or query, and name the exact failed control (object-level authorization, not authentication). For GraphQL, identify missing depth or complexity limits as the cause of denial of service.
The Courseiva GCIH question bank contains 28 questions in the Web App API Attacks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Web App API Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included