GCIH Web App Injection Attacks Practice Question
An incident handler is investigating a web application that uses a NoSQL database (MongoDB). The attacker sent a request with the parameter 'username[$ne]=admin&password[$ne]=wrong' and successfully authenticated as an administrator. Which of the following BEST describes the attack technique used?
⚠ Common exam trap
The trap here is assuming that any authentication bypass involving special characters is SQL injection, when in fact MongoDB operators indicate a NoSQL injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NoSQL injection via operator injection in MongoDB query selectors
The attacker exploited the application's failure to sanitize user input before incorporating it into a MongoDB query. By injecting the $ne operator, the attacker changed the query to return a user record where the username and password are not equal to the supplied values, bypassing authentication. This is a classic NoSQL injection attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection using MongoDB's SQL compatibility layer
Why it's wrong here
MongoDB is a NoSQL database and does not use SQL by default. While some tools provide SQL-like interfaces, the payload uses MongoDB-specific operators like $ne, which are not part of SQL syntax. This is a NoSQL injection, not SQL injection.
- ✗
Cross-Site Scripting (XSS) through unsanitized input in the login form
Why it's wrong here
XSS involves injecting client-side scripts that execute in a victim's browser. The observed attack manipulated database query operators to bypass authentication, which is a server-side injection flaw. XSS would not grant administrative access by itself, and the payload uses MongoDB operators, not JavaScript.
- ✓
NoSQL injection via operator injection in MongoDB query selectors
Why this is correct
The attacker injected MongoDB operators ($ne) into the query parameters. The application likely passed the user input directly into a MongoDB query without sanitization, allowing the attacker to alter the query logic. $ne means 'not equal', so the query returns a user where username is not 'admin' and password is not 'wrong', effectively bypassing authentication.
- ✗
LDAP injection exploiting the authentication backend
Why it's wrong here
LDAP injection targets directory services using LDAP filters. The payload here uses MongoDB operators ($ne) which are specific to NoSQL databases. There is no indication that LDAP is involved. The attack exploits the application's MongoDB query construction, not an LDAP directory.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.