Courseiva

GCIH Exploiting Insecure Web App References Practice Question

An attacker manipulates a URL parameter `?file=invoice_123.pdf` to `?file=../../etc/passwd` on a web server. The application successfully returns the sensitive system file content. Which vulnerability is being exploited?

⚠ Common exam trap

Candidates often confuse Path Traversal with Local File Inclusion (LFI). While related, they fail to identify the specific mechanism of escaping directories using '..' notation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Path Traversal

This scenario describes a Path Traversal attack, where an application fails to validate user input used to construct file system paths. By using dot-dot-slash notation, the attacker escapes the intended directory to access unauthorized files. This represents a critical failure in input validation and access control, commonly leading to full system compromise or sensitive data exposure, necessitating robust file path normalization and strictly defined allow-lists.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-Site Request Forgery

    Why it's wrong here

    Cross-Site Request Forgery involves forcing an authenticated user to execute unwanted actions on a web application in which they are currently authenticated. It relies on ambient authority of browser cookies and does not involve manipulating file path references to access server-side system files directly.

  • ✓

    Path Traversal

    Why this is correct

    Path Traversal exploits insufficient security validation of user-supplied input files. By injecting directory traversal sequences like double-dot-slash, attackers manipulate the server's file system path resolution. This allows unauthorized access to arbitrary files on the underlying operating system that should remain inaccessible to the web application process.

  • ✗

    SQL Injection

    Why it's wrong here

    SQL Injection involves the injection of malicious SQL queries into input fields to manipulate database execution. It targets the interaction between the application and the database engine rather than the file system traversal mechanisms used to access local files through insecure URL references or file parameters.

  • ✗

    Server-Side Request Forgery

    Why it's wrong here

    Server-Side Request Forgery involves inducing the server to make requests to unintended locations, such as internal services or external networks. While it involves manipulating input references, the target is typically network-accessible services rather than local file system objects located on the disk of the web server.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.