GCIH Web App Injection Attacks Practice Question
A security analyst is reviewing an incident where an attacker submitted a specially crafted XML document to a SOAP API endpoint. The XML included a DOCTYPE declaration with an ENTITY that referenced file:///etc/passwd. The server's response contained the contents of that file. Which vulnerability was exploited?
⚠ Common exam trap
The trap here is labeling any server-side request as SSRF, when the use of a file:// entity to read local files is specifically XXE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
XML External Entity (XXE) injection
The attacker exploited an XML parser that resolved external entities, using a file:// URI to read /etc/passwd. This is XML External Entity injection. The SOAP endpoint failed to disable DOCTYPE processing or external entity resolution, allowing the server to disclose local files. The other options describe different attack classes that do not match the XML entity mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-Site Scripting (XSS)
Why it's wrong here
XSS involves injecting client-side scripts into web pages viewed by other users. Here the attacker sent XML to a SOAP API and received file contents, which is a server-side file disclosure. No script execution in a browser is involved, so XSS is not the correct classification.
- ✓
XML External Entity (XXE) injection
Why this is correct
The attacker defined an external entity in the DOCTYPE that pointed to a local file, and the parser resolved it, returning the file's contents. This is the defining behavior of XXE injection. The SOAP endpoint accepted XML and processed the entity without disabling external entity resolution, allowing local file disclosure.
- ✗
Server-Side Request Forgery (SSRF)
Why it's wrong here
SSRF tricks the server into making HTTP requests to internal services. While XXE can sometimes be used to perform SSRF via http:// entities, this scenario uses a file:// entity to read a local file, which is classic XXE file disclosure. SSRF is a different mechanism and not the primary vulnerability here.
- ✗
SQL injection
Why it's wrong here
SQL injection manipulates database queries through user input. The payload here is an XML document with an external entity, not SQL syntax. The returned data is a system file, not database records, so SQL injection does not explain the observed behavior.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.