GCIH Web App API Attacks Practice Question
An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /api/v1/user/details?id=124. This vulnerability indicates a failure in which security control?
⚠ Common exam trap
Candidates sometimes misidentify this as a broken authentication issue or API parameter tampering, missing that direct reference to database keys via predictable parameters defines IDOR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insecure Direct Object Reference
This scenario describes Insecure Direct Object Reference (IDOR). The application fails to verify if the authenticated user has authorization to access the object associated with the ID parameter. In API security, this is a critical flaw because APIs often expose backend database keys directly. Proper mitigation requires server-side access control checks on every request, ensuring the requester owns the resource before returning sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Broken Authentication
Why it's wrong here
Broken authentication involves issues with session management or credential validation mechanisms. While the attacker accesses data, the failure is specifically related to object-level authorization rather than the mechanism used to verify the identity of the user requesting the resource initially.
- ✓
Insecure Direct Object Reference
Why this is correct
IDOR occurs when an application provides direct access to objects based on user-supplied input. By manipulating the ID parameter, the attacker accesses unauthorized data records. APIs are particularly susceptible to this when they rely on sequential IDs for object retrieval without verifying user permissions.
- ✗
Cross-Site Scripting
Why it's wrong here
Cross-Site Scripting involves injecting malicious scripts into web pages viewed by other users. The scenario describes data access manipulation rather than the injection of client-side code execution. IDOR focuses on the backend resource access control logic rather than the presentation layer execution.
- ✗
Insufficient Logging and Monitoring
Why it's wrong here
Insufficient logging refers to the inability of the system to record and alert on suspicious activities. While logging might be lacking, the primary vulnerability that allowed the data access is the lack of authorization checks on the object reference itself, not the logging policy.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.