PEN-200 • Practice Test 5 — 25 Questions
Free PEN-200 practice test 5 — 25 questions with explanations. No signup required.
You are testing a Java-based web application that uses the Spring framework. The application has an endpoint /api/users/{id} that returns user details in JSON. When you request /api/users/123, you receive your own details. You then request /api/users/124 and receive another user's details. The application uses a session cookie but does not implement any role-based checks on this endpoint. What is the MOST appropriate next step to demonstrate the impact of this vulnerability?
Choose an answer to begin — your selection is scored in the full session.
25 questions · instant feedback and full explanations after every question.