Courseiva

GCIH Exploiting Insecure Web App References Practice Question

A security engineer is reviewing a web application that uses a parameter `account` to retrieve account details. The parameter value is a base64-encoded string of the account number, such as `YWNjb3VudD0xMjM0`. An attacker decodes the string, changes the account number, re-encodes it, and successfully accesses another user's account. Which of the following is the most likely reason this attack succeeded?

⚠ Common exam trap

The trap here is assuming that encoding or encrypting an identifier provides security, when in fact authorization checks are still required to prevent IDOR.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application relies on obfuscation instead of proper access control.

The application uses base64 encoding to obfuscate the account number but fails to enforce access control. An attacker can easily decode the parameter, change the account number, and re-encode it. The success of the attack shows that the application relies on the obscurity of the parameter rather than verifying that the authenticated user owns the account. This is a form of IDOR where the direct object reference is encoded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application uses weak encryption that can be broken.

    Why it's wrong here

    Base64 is not encryption at all; it is an encoding scheme. The attacker did not need to break encryption because none was used. The vulnerability stems from missing authorization, not from cryptographic weaknesses. Even strong encryption would not fix IDOR if the application decrypts and then fails to check ownership.

  • ✗

    The application fails to validate the input length, allowing buffer overflow.

    Why it's wrong here

    The scenario does not mention any buffer overflow or input length issues. The attack involved decoding, modifying, and re-encoding a parameter, which is a logic flaw, not a memory corruption issue. Buffer overflows are typically associated with unmanaged code and are unrelated to this IDOR-like vulnerability.

  • ✓

    The application relies on obfuscation instead of proper access control.

    Why this is correct

    Base64 encoding is not encryption; it is easily reversible. The application likely assumes that encoding the account number obscures it, but without server-side authorization checks, an attacker can decode, modify, and re-encode the value. The success indicates that the application does not verify that the authenticated user owns the requested account, relying solely on the obscurity of the parameter.

  • ✗

    The application uses a predictable session token that can be guessed.

    Why it's wrong here

    The attack does not involve session tokens; it involves the `account` parameter. The session token is used for authentication, but the attacker already has a valid session. The issue is that the application does not check if the authenticated user is authorized to access the requested account, regardless of how the account number is represented.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.