Courseiva

GCIH Web App Injection Attacks Practice Question

A GCIH analyst is investigating a web application that uses Java deserialization to process user-supplied session objects. The analyst suspects an attacker exploited an insecure deserialization vulnerability to achieve remote code execution. Which two indicators are most likely to confirm this type of attack? (Choose two.)

⚠ Common exam trap

The trap here is selecting generic compromise indicators like a new admin account, which can result from many attacks and do not specifically confirm deserialization exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HTTP requests containing serialized Java objects with the magic bytes AC ED 00 05 in the body.

Insecure deserialization attacks require delivering a serialized payload, which for Java begins with the AC ED 00 05 magic bytes. Successful exploitation often results in remote code execution, frequently followed by outbound connections for command-and-control or exfiltration. These two indicators together confirm both the delivery and the impact, whereas the other options are either unrelated or nonspecific.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    HTTP requests containing serialized Java objects with the magic bytes AC ED 00 05 in the body.

    Why this is correct

    Java serialization streams begin with the magic bytes AC ED 00 05. Their presence in HTTP request bodies indicates that the application is accepting serialized Java objects from the client. When combined with other suspicious behavior, this is a strong indicator of an insecure deserialization attack attempt, as attackers must deliver a serialized payload to the vulnerable endpoint.

  • ✗

    The presence of a new administrator account created in the application's user database.

    Why it's wrong here

    A new admin account could result from many attack types, including credential stuffing or privilege escalation, and is not specific to deserialization. While it may indicate compromise, it does not directly confirm that a deserialization payload executed. The more specific indicators are the serialized object bytes and the resulting outbound connection.

  • ✗

    Database error messages containing SQL syntax errors.

    Why it's wrong here

    SQL syntax errors point to SQL injection attempts, not Java deserialization. The vulnerable component here processes serialized Java objects, not SQL queries. While both are injection flaws, the indicators differ; SQL errors do not confirm deserialization exploitation and could mislead the investigation.

  • ✓

    Unexpected outbound network connections from the application server to an external IP address shortly after a suspicious request.

    Why this is correct

    Insecure deserialization often leads to remote code execution, and attackers frequently use the compromised server to make outbound connections for command-and-control or data exfiltration. An unexpected outbound connection following a request containing serialized data strongly suggests the payload executed and established a channel. This correlates the delivery mechanism with post-exploitation activity.

  • ✗

    A sudden increase in the number of 404 errors for static image files.

    Why it's wrong here

    404 errors for images indicate broken links or scanning for common files, not deserialization exploitation. Insecure deserialization does not typically cause missing image requests. This indicator is unrelated to the attack mechanism and would not help confirm a deserialization payload execution.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.