GCIH Web App Injection Attacks Practice Question
An incident handler is analyzing a web application that uses a NoSQL database. The application constructs queries by directly embedding user input into JSON objects. An attacker submits a payload that includes `$ne` and `$gt` operators to bypass authentication. Which TWO of the following statements accurately describe this attack or its mitigation? (Choose two.)
⚠ Common exam trap
The trap here is assuming NoSQL databases are immune to injection because they do not use SQL, when in fact they have their own injection vectors via query operators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attack is a NoSQL injection that exploits the lack of input sanitization in query operators.
NoSQL injection exploits unsanitized input that is interpreted as query operators, allowing authentication bypass or data manipulation. Effective mitigation includes using parameterized queries or ORMs, and sanitizing input to remove special operators. Incident handlers should review application code for direct concatenation of user input into NoSQL queries and check database logs for unusual operator usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The attack is only possible if the application uses MongoDB; other NoSQL databases are immune.
Why it's wrong here
NoSQL injection is not limited to MongoDB. Other NoSQL databases such as CouchDB, Cassandra, and Redis can also be vulnerable if user input is improperly handled. The underlying issue is the lack of input sanitization, not the specific database product. Therefore, claiming immunity for other NoSQL databases is false and could lead to a false sense of security.
- ✓
The attack is a NoSQL injection that exploits the lack of input sanitization in query operators.
Why this is correct
NoSQL injection occurs when user input is not properly sanitized before being included in a NoSQL query. Operators like `$ne` (not equal) and `$gt` (greater than) can alter query logic. For example, injecting `{"$ne": null}` into a password field can bypass authentication by matching any non-null value. This statement correctly identifies the attack type and its root cause.
- ✗
The attack can be mitigated by enabling strict mode in the NoSQL database, which blocks all operator usage.
Why it's wrong here
While some databases have strict mode or schema validation, it does not universally block operator usage in queries. Operators are legitimate features for querying. Enabling strict mode might affect other functionality and is not a standard mitigation for injection. Proper input handling is required instead. This statement is misleading and not a recognized best practice.
- ✗
The attack is a form of SQL injection because NoSQL databases use SQL-like syntax.
Why it's wrong here
NoSQL databases do not use SQL; they use document, key-value, or graph models. While some NoSQL databases support SQL-like query languages, the injection here leverages NoSQL-specific operators like `$ne` and `$gt`, which are not SQL syntax. Therefore, classifying it as SQL injection is incorrect and could lead to inappropriate remediation.
- ✓
The attack can be prevented by using parameterized queries or an ORM that safely handles user input.
Why this is correct
Parameterized queries or ORMs separate data from query logic, preventing user input from being interpreted as operators or query structure. For NoSQL databases like MongoDB, using the official driver's query builder or sanitizing input to strip `$` operators is effective. This statement is a valid mitigation strategy for NoSQL injection.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.