GCIH Exploiting Insecure Web App References Practice Question
A security analyst is investigating a suspected local file inclusion (LFI) attack against a PHP web application. The web server logs show the following request: `GET /download.php?file=php://filter/convert.base64-encode/resource=index.php`. The analyst needs to determine the attacker's objective and the potential impact. (Choose two.)
⚠ Common exam trap
The trap here is assuming that any file inclusion attack aims to read `/etc/passwd`, when the use of `php://filter` specifically targets PHP source code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attacker is attempting to read the source code of `index.php` by encoding it in Base64 to bypass PHP execution.
The payload uses the `php://filter` wrapper with Base64 encoding to read the source code of `index.php`. This technique bypasses PHP execution, allowing the attacker to view the raw code, which may contain sensitive information like database credentials. The other options misidentify the objective, such as command execution or CSRF, which are not supported by the specific payload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The attacker is attempting to read the source code of `index.php` by encoding it in Base64 to bypass PHP execution.
Why this is correct
The `php://filter` wrapper with `convert.base64-encode` is a known technique to read PHP source code. Normally, including a PHP file would execute it, but by Base64-encoding the output, the attacker can view the raw source, which may contain sensitive logic or credentials. This is a direct objective of the attack.
- ✗
The attacker is attempting to retrieve the contents of a sensitive file, such as `/etc/passwd`, by including it directly.
Why it's wrong here
While LFI can be used to read `/etc/passwd`, the specific payload targets `index.php` via a PHP filter. The use of `php://filter` and Base64 encoding indicates an attempt to read PHP source code, not a system file. Reading `/etc/passwd` would typically use a direct path like `../../../../etc/passwd` without the filter wrapper.
- ✗
The attacker is attempting to perform a cross-site request forgery (CSRF) attack against the web application.
Why it's wrong here
CSRF involves tricking a victim's browser into sending an authenticated request, often via a crafted link or form. The observed request is a direct GET to the server with a malicious parameter, not a CSRF vector. The payload aims to read files, not to perform actions on behalf of a user.
- ✗
The attacker is attempting to execute arbitrary commands on the server via the `file` parameter.
Why it's wrong here
The payload uses the `php://filter` stream wrapper, which is for filtering file streams, not for command execution. Command execution would typically involve wrappers like `expect://` or `data://` with code, or log poisoning combined with inclusion. Here, the goal is information disclosure, not remote code execution.
- ✓
The attacker is exploiting a vulnerability that could lead to disclosure of application source code, potentially revealing database credentials.
Why this is correct
By successfully reading `index.php` source, the attacker may find hardcoded credentials, database connection strings, or other secrets. This is a significant impact because it can lead to further compromise. The use of Base64 encoding is specifically to avoid PHP execution and view the code, confirming the objective of source code disclosure.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.