Courseiva
Web App API Attacks →hardMultiple Select

GCIH Web App API Attacks Practice Question

A GCIH incident responder is investigating a suspected API attack where an attacker manipulated a JSON Web Token (JWT) to gain unauthorized access. The responder needs to identify which two conditions would allow a JWT 'kid' (Key ID) header injection attack to succeed. (Choose two.)

⚠ Common exam trap

The trap here is conflating 'kid' injection with other JWT attacks like 'none' algorithm or weak secret, which require different conditions and do not involve the 'kid' header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application allows the 'kid' header to specify an absolute path or URL that the server will fetch to obtain the key.

JWT 'kid' injection succeeds when the application uses the 'kid' header to determine the verification key without validating its content. If the 'kid' is used to build a file path or fetch a remote key, an attacker can manipulate it to use a key they control, forging valid tokens. The other conditions describe different JWT weaknesses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application uses a symmetric signing algorithm and the secret is weak or guessable.

    Why it's wrong here

    A weak secret enables brute-force or dictionary attacks on the JWT signature, but it is not a condition for 'kid' injection. 'kid' injection exploits how the key is selected, not the strength of the key itself. Therefore, this is not a required condition.

  • ✓

    The application allows the 'kid' header to specify an absolute path or URL that the server will fetch to obtain the key.

    Why this is correct

    If the server fetches the key from a location specified by the 'kid' header, an attacker can point it to a malicious server hosting a key they control, or to a local file. This allows the attacker to sign tokens with a key the server will trust, bypassing authentication.

  • ✓

    The application uses the 'kid' value to construct a file path for retrieving the verification key without proper sanitization.

    Why this is correct

    If the 'kid' parameter is used to build a file path, an attacker can inject directory traversal sequences to point to a known file, such as /dev/null or a public key file, causing the application to use an attacker-controlled or predictable key. This is the core of kid injection.

  • ✗

    The JWT is transmitted over an unencrypted HTTP connection, allowing token interception.

    Why it's wrong here

    Transmitting JWT over HTTP exposes it to interception, but that is a separate issue from 'kid' injection. 'kid' injection requires the server to process the 'kid' header in an unsafe manner, not merely that the token is sent insecurely. Thus, this condition does not enable 'kid' injection.

  • ✗

    The application supports the 'none' algorithm and accepts unsigned tokens.

    Why it's wrong here

    The 'none' algorithm attack is a separate JWT vulnerability where the signature is omitted. While it can lead to unauthorized access, it does not involve the 'kid' header. The question specifically asks about 'kid' injection, so this condition is not relevant.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.