GCIH Web App API Attacks Practice Question
A GCIH incident handler is reviewing web server logs after a suspected API reconnaissance campaign. The logs show numerous requests to endpoints such as /api/v1/users, /api/v2/users, /api/v3/users, and /api/internal/users, all returning HTTP 404 except one. Which attack technique is most consistent with this pattern?
⚠ Common exam trap
The trap here is assuming that repeated 404 responses indicate a failed attack, when in fact they are the expected outcome of enumeration that successfully identifies a valid API version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
API version enumeration
The pattern of requests to multiple API version prefixes and internal-looking paths, with only one returning a non-404 response, indicates deliberate version and endpoint enumeration. Attackers use this to map the API surface and find versions that may be deprecated, unpatched, or less protected, which then become targets for further exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site scripting (XSS) in API responses
Why it's wrong here
XSS involves injecting client-side scripts that execute in a victim's browser, not probing server-side API paths for version discovery. The logs show no injected script payloads or browser interactions; they show direct requests to different API paths. Therefore, this pattern does not indicate XSS.
- ✓
API version enumeration
Why this is correct
The attacker systematically probes multiple API version prefixes and internal paths to discover which versions are live and may lack security controls. The single successful response reveals a valid version, making version enumeration the technique in use. This is a common precursor to exploiting deprecated or unpatched API versions.
- ✗
Server-side request forgery (SSRF) via API parameters
Why it's wrong here
SSRF occurs when an API fetches a user-supplied URL, causing the server to make requests to internal or external systems. Here, the attacker is directly requesting API endpoints, not manipulating a parameter to make the server issue requests. No SSRF indicators such as URL parameters are present.
- ✗
JWT algorithm confusion attack
Why it's wrong here
JWT algorithm confusion involves manipulating the token's header to force a weaker verification algorithm, typically after obtaining a valid token. The described log activity shows unauthenticated probing of API paths, not token manipulation. Thus, this technique is not supported by the evidence.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.