Courseiva

GCIH Exploiting Insecure Web App References Practice Question

A security analyst is reviewing a web application that uses a parameter `doc_id` to retrieve documents from a database. The application does not validate that the requested document belongs to the authenticated user. During an incident response, the analyst observes multiple requests with sequential `doc_id` values from a single IP address. Which TWO of the following actions should the analyst take to confirm and mitigate the IDOR vulnerability? (Choose two.)

⚠ Common exam trap

Many candidates confuse obfuscation with security; encoding an identifier does not prevent IDOR if authorization checks are missing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Replay the requests with a different user session to verify if unauthorized access is possible.

To confirm IDOR, the analyst should test with a different user session to see if unauthorized access occurs. To mitigate, the application must enforce server-side authorization checks that verify the authenticated user owns the requested document. These two actions address both validation and remediation. Obfuscation, error messages, and rate-limiting do not fix the root cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Replay the requests with a different user session to verify if unauthorized access is possible.

    Why this is correct

    Replaying the requests with another user's session tests whether the application enforces object-level authorization. If the second user can access documents belonging to the first user, it confirms IDOR. This is a standard validation step because it isolates the authorization check from other factors like session validity.

  • ✗

    Rate-limit requests from the suspicious IP address to stop the enumeration.

    Why it's wrong here

    Rate-limiting may slow down an attacker but does not fix the underlying IDOR vulnerability. The attacker could use multiple IPs or slow the attack. It also does not confirm the vulnerability; it is a temporary control. The core issue is missing access control, which must be remediated.

  • ✗

    Obfuscate the `doc_id` parameter by base64-encoding it to prevent enumeration.

    Why it's wrong here

    Base64 encoding is not encryption; it is trivially reversible. An attacker can decode and modify the value. While it may slow down casual enumeration, it does not fix the missing authorization check. This is a weak mitigation and does not confirm the vulnerability; it only obscures it.

  • ✓

    Implement a server-side check that compares the authenticated user's ID with the owner ID of the requested document.

    Why this is correct

    The most effective mitigation is to enforce access control on the server for each object request. By comparing the authenticated user's identity to the document's owner, the application prevents unauthorized access. This addresses the root cause of IDOR and ensures that even if an attacker guesses a valid `doc_id`, they cannot retrieve it without proper authorization.

  • ✗

    Enable detailed error messages to help developers debug the issue.

    Why it's wrong here

    Detailed error messages can leak sensitive information and aid attackers, not mitigate IDOR. They do not address the authorization flaw and may expose internal paths or database details. This action is counterproductive for security and does not help confirm the vulnerability.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.