Courseiva

GCIH Exploiting Insecure Web App References Practice Question

A web application serves user-uploaded documents through a request to `/api/v1/documents/{docGuid}`. The `docGuid` is a version 4 UUID that appears unguessable, and the API returns the document for any authenticated user who supplies a valid GUID. During an incident-handling review, you note that the GUID is also exposed in a public activity feed that lists recent uploads. What is the most significant reference-handling weakness in this design?

⚠ Common exam trap

The trap here is assuming that a random, unguessable identifier such as a version 4 UUID is itself a security control that prevents insecure direct object reference attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application relies on the UUID's unguessability for authorization instead of verifying that the requesting user owns the document.

The API treats the document GUID as a bearer credential for the object. Because the GUID is disclosed in a public feed, any authenticated user can collect references and retrieve documents belonging to others. Secure designs must resolve the reference to an object and then verify the authenticated principal is entitled to it, rather than assuming an unguessable identifier is sufficient protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The API should hash each GUID with SHA-256 before returning it so that clients cannot correlate documents.

    Why it's wrong here

    Hashing a GUID that is already public in the feed does not stop an attacker from copying the hashed value and replaying it. The server would still resolve that value to the document without checking ownership. Hashing identifiers adds complexity without creating an authorization boundary, so the underlying reference weakness remains fully exploitable.

  • ✗

    The version 4 UUID does not contain a timestamp, so the application cannot determine when the document was created.

    Why it's wrong here

    UUID version 4 is random and intentionally carries no timestamp; that is unrelated to access control. Creation time should come from a database column, not from the identifier. Even if the UUID encoded a timestamp, the API would still return documents to any authenticated user, so this does not address the actual reference-authorization flaw in the scenario.

  • ✓

    The application relies on the UUID's unguessability for authorization instead of verifying that the requesting user owns the document.

    Why this is correct

    Unpredictable identifiers are not an access control mechanism. Because the API never checks ownership, any authenticated user who obtains a GUID from the public activity feed can retrieve another user's document. This is the defining property of an insecure direct object reference: the object reference itself functions as the authorization decision, which breaks as soon as the reference leaks.

  • ✗

    The activity feed should use a POST request instead of a GET request to hide the GUIDs from intermediaries.

    Why it's wrong here

    Changing the HTTP method of the feed does not conceal the GUIDs from users who can already view the feed, and it conflicts with safe, cacheable read semantics. The vulnerability is that possession of the reference grants access, not the verb used to publish the feed. Switching methods would not prevent unauthorized document retrieval.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.