Courseiva
Web App API Attacks →hardMultiple Choice

GCIH Web App API Attacks Practice Question

A GCIH analyst is called after a SaaS provider reports that an integration partner's API traffic began returning other tenants' records. The partner's client was calling /api/v3/documents/{documentId} and had recently started sending a second header, X-Tenant-Id, that the gateway trusts to route requests. The analyst confirms the partner is authenticated with a valid OAuth 2.0 bearer token scoped to its own tenant. Which weakness allowed the cross-tenant exposure?

⚠ Common exam trap

The trap here is focusing on token validity or ID enumeration while missing that a client-controlled routing header silently overrode the tenant boundary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The API trusted a client-supplied header for tenant routing instead of deriving tenant scope from the authenticated token claims

The gateway trusted an attacker-controllable header to decide which tenant's data to return while authorization relied solely on the caller's own bearer token. Because tenant selection and authorization were decoupled, any authenticated caller could request another tenant's documents by naming that tenant in the header. The fix is to derive tenant scope from verified token claims or server-side state and ignore client-supplied routing headers for authorization decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The document IDs were sequential integers, allowing enumeration of other tenants' records by incrementing the identifier

    Why it's wrong here

    Identifier enumeration explains unauthorized access when the API fails to check ownership of each requested object, and it would show up as many requests with different IDs. In this case the partner's traffic was normal until the second header appeared, and the gateway used that header to select the tenant, so sequential identifiers are not the root cause of the cross-tenant leak.

  • ✗

    The OAuth 2.0 bearer token was forged because the partner guessed the signing key used by the authorization server

    Why it's wrong here

    Nothing in the scenario indicates a forged or tampered token; the partner holds a legitimately issued token scoped to its own tenant, and the provider still reports valid authentication. Guessing a signing key would let the attacker mint arbitrary tokens, but here the token is genuine and the exposure arises from header-based routing, so key compromise is not the mechanism at work.

  • ✗

    The integration partner exploited a race condition in the API's caching layer to retrieve stale responses belonging to other tenants

    Why it's wrong here

    A caching race condition would produce intermittent, timing-dependent leakage that is difficult to reproduce and would not correlate cleanly with the introduction of a new request header. The reported behavior began exactly when the X-Tenant-Id header was added, which points to deterministic routing based on that header rather than a nondeterministic cache timing flaw.

  • ✓

    The API trusted a client-supplied header for tenant routing instead of deriving tenant scope from the authenticated token claims

    Why this is correct

    Because the gateway routes on the attacker-controllable X-Tenant-Id header while authorization relies only on the bearer token, an authenticated partner can name any tenant and receive its documents. The tenant boundary should be derived from a verified token claim or server-side session, never from a header the caller can set. This is a broken authorization design flaw rather than a token forgery or injection issue.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.