Courseiva

GCIH Exploiting Insecure Web App References Practice Question

A web application allows users to download files by specifying a filename in the URL, such as `download?file=report.pdf`. An attacker changes the parameter to `download?file=../../../../etc/passwd` and successfully retrieves the system's password file. Which of the following best describes this attack?

⚠ Common exam trap

A common mix-up: candidates confuse Path Traversal with IDOR, but IDOR involves accessing objects by reference, not navigating the file system with directory traversal sequences.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Path Traversal

The attacker manipulates the `file` parameter with `../` sequences to escape the intended directory and read a system file. This is a classic Path Traversal attack. The application fails to validate or sanitize the user-supplied path, allowing access to files outside the web root. The successful retrieval of `/etc/passwd` demonstrates the vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remote File Inclusion (RFI)

    Why it's wrong here

    RFI involves including a remote file, often from an attacker-controlled server, to execute code. In this scenario, the attacker is accessing a local file on the server, not including a remote one. The attack does not involve executing code from a remote source, so RFI is not applicable.

  • ✗

    Insecure Direct Object Reference (IDOR)

    Why it's wrong here

    IDOR involves accessing objects by manipulating an identifier, but the object is typically a database record or a file that the user is not authorized to access. Here, the attacker is traversing the file system to reach a system file, which is a path traversal issue. IDOR would be if the attacker accessed another user's report by changing an ID, not by using directory traversal sequences.

  • ✗

    Cross-Site Scripting (XSS)

    Why it's wrong here

    XSS involves injecting client-side scripts into web pages viewed by other users. This attack targets the server's file system and does not involve script injection or execution in a victim's browser. The outcome is unauthorized file access, not script execution.

  • ✓

    Path Traversal

    Why this is correct

    The attacker uses `../` sequences to navigate outside the intended directory and access a system file. This is the definition of Path Traversal, also known as directory traversal. The application fails to sanitize the file path, allowing access to files outside the web root. The success of retrieving `/etc/passwd` confirms the vulnerability.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.