GCIH Exploiting Insecure Web App References Practice Question
A penetration tester is assessing a RESTful API that manages user orders. The endpoint to retrieve an order is `GET /api/orders/{orderId}`. The tester, authenticated as user Alice, captures a request for her own order with `orderId=1001`. She then modifies the request to `orderId=1002` and receives the order details belonging to user Bob, including Bob's shipping address and items. The application did not check if the order belonged to Alice. Which type of vulnerability is this?
⚠ Common exam trap
The trap here is assuming that because the API uses a numeric ID, the vulnerability must be SQL injection, but the key indicator is the successful access to another user's data by simply changing the ID without any injection syntax.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insecure Direct Object Reference (IDOR)
The tester modified the orderId parameter from her own order to another user's order and successfully retrieved data, indicating that the application does not verify whether the authenticated user owns the requested order. This is a direct object reference without proper authorization checks, which is the definition of IDOR. The other options describe different attack classes that do not match the observed behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-Site Request Forgery (CSRF)
Why it's wrong here
CSRF tricks a victim's browser into sending an authenticated request to a vulnerable site, often to perform state-changing actions. In this scenario, the tester is directly modifying API requests using her own authenticated session, not forcing another user's browser to act. The issue is unauthorized access to data due to missing authorization checks, not a forgery of requests from a trusted user.
- ✗
SQL Injection
Why it's wrong here
SQL injection involves manipulating input to alter database queries, often leading to data leakage or modification. Here, the tester simply changed the orderId value in the URL path; there is no evidence of injecting SQL syntax or altering the query structure. The server likely executed a legitimate query for the provided orderId, but failed to enforce authorization, which is characteristic of IDOR, not SQL injection.
- ✓
Insecure Direct Object Reference (IDOR)
Why this is correct
IDOR occurs when an application exposes a reference to an internal object, such as a database key, and fails to verify that the requesting user is authorized to access that object. In this scenario, the orderId directly references an order, and the API does not check ownership, allowing Alice to access Bob's order by simply changing the ID. This is a classic horizontal privilege escalation via IDOR.
- ✗
Server-Side Request Forgery (SSRF)
Why it's wrong here
SSRF occurs when an attacker can make the server perform requests to internal or external resources, often bypassing network controls. Here, the tester is directly accessing an API endpoint and receiving order data; the server is not being tricked into making a request to another system. The vulnerability stems from missing object-level authorization, not from server-initiated requests.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.