PEN-200 • Practice Test 11
Free PEN-200 practice test — 15 questions with explanations. Set 11. No signup required.
You are testing a Java-based web application that uses the Spring framework. The application has an endpoint /api/users/{id} that returns user details in JSON. When you request /api/users/123, you receive your own details. You then request /api/users/124 and receive another user's details. The application uses a session cookie but does not implement any role-based checks on this endpoint. What is the MOST appropriate next step to demonstrate the impact of this vulnerability?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.