Courseiva

GCIH Exploiting Insecure Web App References Practice Question

An application generates invoice PDFs on demand and caches them under `/var/app/cache/<userId>/<invoiceId>.pdf`. The download handler builds the path with `Paths.get(cacheRoot, userId, invoiceId + ".pdf")` and calls `Files.exists` before streaming. During an incident review, a crafted `invoiceId` value of `../../../../etc/hosts%00` produced a successful read. Which factor best explains why the containment check failed?

⚠ Common exam trap

The trap here is assuming that calling `Files.exists` on a constructed path provides safety, when existence checks say nothing about whether the path stayed inside the intended directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The null byte was decoded before filesystem access, and the traversal segments were never canonicalized and compared against the cache root.

Path containment fails when the code concatenates user input, decodes it, and then checks the filesystem without canonicalizing the result. The traversal segments escape the cache root, and the trailing null byte can truncate the appended extension on affected platforms. The reliable pattern is to decode exactly once, reject null bytes and separators, canonicalize the resolved path, and confirm it still begins with the canonical cache root before any file operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application checks `Files.exists` before authentication completes, so unauthenticated users can probe arbitrary paths on the server.

    Why it's wrong here

    The scenario does not indicate an authentication ordering problem, and the payload targets a specific file whose content was returned. Even an authenticated user could supply the same crafted identifier. The decisive gap is that the constructed path was never canonicalized and verified to remain within the cache root before the existence check and stream.

  • ✗

    The `Files.exists` call follows symbolic links by default, so an attacker can point the invoice path at a symlink outside the cache root.

    Why it's wrong here

    Symbolic link following is a real concern, but the observed payload is a traversal sequence with a null byte, not a link. There is no evidence a symlink was created in the cache directory. The escape came from path construction and missing canonicalization, so link-following behavior is not the factor that explains this particular successful read.

  • ✓

    The null byte was decoded before filesystem access, and the traversal segments were never canonicalized and compared against the cache root.

    Why this is correct

    The payload combines traversal with a trailing null byte. If the decoder produces a NUL and the code concatenates before canonicalizing, the resulting path can escape the cache root, and the null may truncate the extension on platforms that honor it. Because no canonical containment check ran, `Files.exists` simply confirmed the escaped path and the file was streamed.

  • ✗

    The per-user cache directory is writable by the application, so an attacker can overwrite the invoice file with the contents of the target file.

    Why it's wrong here

    Writing into the cache directory would let an attacker plant content, but the incident involved reading a system file, not modifying cache contents. The traversal payload directs the read outside the cache root. Writable cache permissions are a separate hardening concern and do not explain how the crafted identifier caused `Files.exists` to confirm an out-of-root path.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.