Courseiva
Web App Injection Attacks →mediumMultiple Choice

GCIH Web App Injection Attacks Practice Question

An incident handler is investigating a web application that uses a NoSQL database (MongoDB). The attacker sent a request with the parameter 'username[$ne]=admin&password[$ne]=wrong' and successfully authenticated as an administrator. Which of the following BEST describes the attack technique used?

⚠ Common exam trap

The trap here is assuming that any authentication bypass involving special characters is SQL injection, when in fact MongoDB operators indicate a NoSQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NoSQL injection via operator injection in MongoDB query selectors

The attacker exploited the application's failure to sanitize user input before incorporating it into a MongoDB query. By injecting the $ne operator, the attacker changed the query to return a user record where the username and password are not equal to the supplied values, bypassing authentication. This is a classic NoSQL injection attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection using MongoDB's SQL compatibility layer

    Why it's wrong here

    MongoDB is a NoSQL database and does not use SQL by default. While some tools provide SQL-like interfaces, the payload uses MongoDB-specific operators like $ne, which are not part of SQL syntax. This is a NoSQL injection, not SQL injection.

  • ✗

    Cross-Site Scripting (XSS) through unsanitized input in the login form

    Why it's wrong here

    XSS involves injecting client-side scripts that execute in a victim's browser. The observed attack manipulated database query operators to bypass authentication, which is a server-side injection flaw. XSS would not grant administrative access by itself, and the payload uses MongoDB operators, not JavaScript.

  • ✓

    NoSQL injection via operator injection in MongoDB query selectors

    Why this is correct

    The attacker injected MongoDB operators ($ne) into the query parameters. The application likely passed the user input directly into a MongoDB query without sanitization, allowing the attacker to alter the query logic. $ne means 'not equal', so the query returns a user where username is not 'admin' and password is not 'wrong', effectively bypassing authentication.

  • ✗

    LDAP injection exploiting the authentication backend

    Why it's wrong here

    LDAP injection targets directory services using LDAP filters. The payload here uses MongoDB operators ($ne) which are specific to NoSQL databases. There is no indication that LDAP is involved. The attack exploits the application's MongoDB query construction, not an LDAP directory.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.