Candidates must read logs, exhibits, or code to classify the injection type, then pick the correct defensive control. The single most important thing is distinguishing SQL injection, XSS, and path traversal by how input is used and reflected, not by payload appearance alone.
Start practicing
Web App Injection Attacks — choose a session length
Free · No account required
Domain overview
This domain covers injection flaws in web applications: SQL injection via dynamic query construction, reflected and stored XSS, path traversal using encoded sequences, and command injection. GCIH questions present logs, exhibits, or code snippets and require identifying the vulnerability class, extracting attacker intent, and selecting effective defensive configurations.
Exam objectives
Identifying SQL injection when user input dynamically builds SQL statements and schema names are extracted
Recognizing reflected XSS where input lands in an HTML value attribute without output encoding
Detecting path traversal via q parameters containing ../../../etc/passwd or ....//....//etc/shadow
Choosing defenses like parameterized queries, HttpOnly cookies, input validation, and context-aware output encoding
Confusing reflected XSS with stored XSS when the exhibit only shows immediate reflection in a value attribute
Assuming HttpOnly cookies stop XSS execution rather than only blocking JavaScript access to session cookies
Missing path traversal when payloads use obfuscated sequences like ....// instead of plain ../
Click any question to see the full explanation and answer options, or start a focused practice session above.
An incident responder investigates a web application running a legacy PHP backend. Users report that searching for specific product SKUs causes the application to dump database table structures directly onto the results page. Which underlying vulnerability class is most likely responsible for this behavior?
2An incident handler is analyzing an incident where a web application was compromised via SQL injection. The backend database uses a modern relational database management system. Which TWO of the following remediation strategies are considered primary defenses against SQL injection attacks? (Choose TWO)
3An organization discovers that an attacker executed operating system commands via a vulnerable web application endpoint. The application takes user input, constructs an XML payload, and passes it to an underlying XML parser without disabling external entity resolution. Which type of vulnerability enabled this command execution?
4During an incident response engagement involving a web application, an analyst uncovers evidence of Command Injection. Which TWO indicators or technical conditions strongly support this specific finding? (Choose TWO)
5An incident investigator reviews application logs showing that an attacker manipulated session tokens by altering underlying JSON Web Tokens without knowing the signing secret. The attacker successfully forged valid-looking administrative sessions. Which server-side vulnerability enabled this behavior?
6Which TWO of the following techniques are most effective for preventing Cross-Site Scripting (XSS) in a web application?
7Refer to the exhibit. An application reflects user input directly into the HTML value attribute. What type of vulnerability is present?
8Which of the following describes the primary danger of an Insecure Deserialization vulnerability in a web application?
9What is the primary difference between Stored XSS and Reflected XSS?
10Refer to the exhibit. If an attacker successfully injects <script>alert(1)</script> into a page, what happens?
11When evaluating potential SQL injection in an application, what is the most significant indicator that an application is vulnerable?
12An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data by appending UNION SELECT statements to a numeric product ID parameter. Which backend remediation approach directly eliminates this vulnerability class while preserving application functionality?
13An incident handler is analyzing a severe Cross-Site Scripting (XSS) incident where malicious JavaScript stole administrator session cookies. Which TWO of the following defensive configurations and practices effectively mitigate session theft risks via XSS?
14During a web application penetration test, an assessor discovers an endpoint vulnerable to OS Command Injection via an improperly sanitized ping utility parameter. Which TWO remediation strategies provide robust defense against command injection vulnerabilities?
15An incident responder analyzes a web application log and discovers that an attacker successfully extracted database schema names by manipulating a parameter where the application dynamically constructs SQL statements. The database error messages returned verbose structural details. Which remediation strategy provides the most robust defense against this injection vector while maintaining application functionality?
16An incident handler is reviewing WAF logs and notices repeated HTTP requests to a web application where the 'Host' header contains an attacker-controlled domain, while the request line targets the legitimate application server. The application uses the Host header to construct password-reset links emailed to users. Which web application injection attack class BEST describes this activity?
17An incident handler is investigating a web application that uses a NoSQL database (MongoDB). The attacker sent a request with the parameter 'username[$ne]=admin&password[$ne]=wrong' and successfully authenticated as an administrator. Which of the following BEST describes the attack technique used?
18A GCIH analyst is reviewing web server logs and sees repeated requests to /search?q=... where the q parameter contains strings like ../../../etc/passwd and ....//....//etc/shadow. The responses include root:x:0:0 entries. The application is a Java servlet that concatenates a user-supplied filename onto a base directory before calling new File(baseDir + userInput). Which vulnerability class best describes this incident?
19During incident response at a financial firm, an analyst discovers that a web application's login form is vulnerable to SQL injection. The backend is Microsoft SQL Server, and the application account has sysadmin rights. The attacker's payloads include ; EXEC xp_cmdshell 'whoami' -- and responses show the web server's service account name. Which immediate containment action best limits further damage while preserving evidence?
20During an incident response engagement, you discover that a web application constructs LDAP search filters by concatenating user input directly into the filter string. An attacker submits the username `*)(uid=*))(|(uid=*` into the login form and successfully authenticates as the first user in the directory. Which vulnerability class does this behavior represent?
21An incident handler is examining a web application that stores user profiles in a MySQL database. A recent breach exposed data through a query that the application builds as: SELECT * FROM profiles WHERE username = '" + userInput + "'. The handler wants to recommend a code-level fix that eliminates this class of vulnerability. Which approach should be recommended?
22An incident handler is investigating a web application that uses a templating engine. The application allows users to submit their name, which is later rendered in a greeting page. An attacker submits the payload `{{7*7}}` and the page displays `49`. The application also exposes an endpoint that accepts a template name as a parameter. Which vulnerability is most likely present?
23A security analyst is reviewing an incident where an attacker submitted a specially crafted XML document to a SOAP API endpoint. The XML included a DOCTYPE declaration with an ENTITY that referenced file:///etc/passwd. The server's response contained the contents of that file. Which vulnerability was exploited?
24A security analyst notices that a web application reflects user-supplied input directly into an HTML attribute without encoding. An attacker crafts a URL that, when clicked by a victim, causes the victim's browser to execute a script that reads the victim's session cookie and sends it to an attacker-controlled server. Which type of attack is this?
25A GCIH analyst is investigating a web application that uses Java deserialization to process user-supplied session objects. The analyst suspects an attacker exploited an insecure deserialization vulnerability to achieve remote code execution. Which two indicators are most likely to confirm this type of attack? (Choose two.)
26An incident handler is analyzing a web application that uses a NoSQL database. The application constructs queries by directly embedding user input into JSON objects. An attacker submits a payload that includes `$ne` and `$gt` operators to bypass authentication. Which TWO of the following statements accurately describe this attack or its mitigation? (Choose two.)
27An incident handler is investigating a web application that allows users to upload profile pictures. The application stores uploaded files in a directory accessible via the web and uses the original filename without sanitization. An attacker uploads a file named `shell.php.jpg` containing PHP code. The server executes the file when accessed via its URL. Which vulnerability has been exploited?
28During an incident response engagement at a healthcare portal, an analyst reviews an Apache access.log entry: GET /report.php?view=..%2f..%2f..%2f..%2fetc%2fpasswd HTTP/1.1 with a 200 response size of 1845 bytes. The application runs as www-data on Linux and the 'view' parameter is passed directly to readfile() without sanitization. Which web application injection attack class best describes what the attacker successfully executed?
Candidates must read logs, exhibits, or code to classify the injection type, then pick the correct defensive control. The single most important thing is distinguishing SQL injection, XSS, and path traversal by how input is used and reflected, not by payload appearance alone.
The Courseiva GCIH question bank contains 28 questions in the Web App Injection Attacks domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Web App Injection Attacks domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included