GCIH Web App API Attacks Practice Question
A GCIH analyst is called after a SaaS provider reports that an integration partner's API traffic began returning other tenants' records. The partner's client was calling /api/v3/documents/{documentId} and had recently started sending a second header, X-Tenant-Id, that the gateway trusts to route requests. The analyst confirms the partner is authenticated with a valid OAuth 2.0 bearer token scoped to its own tenant. Which weakness allowed the cross-tenant exposure?
⚠ Common exam trap
The trap here is focusing on token validity or ID enumeration while missing that a client-controlled routing header silently overrode the tenant boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The API trusted a client-supplied header for tenant routing instead of deriving tenant scope from the authenticated token claims
The gateway trusted an attacker-controllable header to decide which tenant's data to return while authorization relied solely on the caller's own bearer token. Because tenant selection and authorization were decoupled, any authenticated caller could request another tenant's documents by naming that tenant in the header. The fix is to derive tenant scope from verified token claims or server-side state and ignore client-supplied routing headers for authorization decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The document IDs were sequential integers, allowing enumeration of other tenants' records by incrementing the identifier
Why it's wrong here
Identifier enumeration explains unauthorized access when the API fails to check ownership of each requested object, and it would show up as many requests with different IDs. In this case the partner's traffic was normal until the second header appeared, and the gateway used that header to select the tenant, so sequential identifiers are not the root cause of the cross-tenant leak.
- ✗
The OAuth 2.0 bearer token was forged because the partner guessed the signing key used by the authorization server
Why it's wrong here
Nothing in the scenario indicates a forged or tampered token; the partner holds a legitimately issued token scoped to its own tenant, and the provider still reports valid authentication. Guessing a signing key would let the attacker mint arbitrary tokens, but here the token is genuine and the exposure arises from header-based routing, so key compromise is not the mechanism at work.
- ✗
The integration partner exploited a race condition in the API's caching layer to retrieve stale responses belonging to other tenants
Why it's wrong here
A caching race condition would produce intermittent, timing-dependent leakage that is difficult to reproduce and would not correlate cleanly with the introduction of a new request header. The reported behavior began exactly when the X-Tenant-Id header was added, which points to deterministic routing based on that header rather than a nondeterministic cache timing flaw.
- ✓
The API trusted a client-supplied header for tenant routing instead of deriving tenant scope from the authenticated token claims
Why this is correct
Because the gateway routes on the attacker-controllable X-Tenant-Id header while authorization relies only on the bearer token, an authenticated partner can name any tenant and receive its documents. The tenant boundary should be derived from a verified token claim or server-side session, never from a header the caller can set. This is a broken authorization design flaw rather than a token forgery or injection issue.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.