GCIH Web App API Attacks Practice Question
An incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?
⚠ Common exam trap
Test-takers often mix up BOLA and IDOR or confuse them with broken function-level authorization, overlooking that resource-specific object manipulation points squarely to object-level flaws.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Broken Object Level Authorization
This scenario clearly demonstrates Broken Object Level Authorization, where authorization validation is missing in the object identifier tier. Attackers exploit this design flaw to harvest unauthorized records horizontally or vertically. Incident handlers must recognize API1:2023 risks during web application forensics to properly scope data exfiltration incidents and remediate flawed access control logic across microservices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-Site Request Forgery
Why it's wrong here
Cross-Site Request Forgery forces authenticated users to execute unintended state-changing actions under their current session. The described scenario involves direct parameter manipulation to query unauthorized resources rather than forging requests via third-party malicious websites leveraging browser cookie persistence mechanisms.
- ✓
Broken Object Level Authorization
Why this is correct
APIs frequently expose endpoints that handle object identifiers, creating a wide attack surface for object-level access control flaws. Without proper authorization validation verifying whether the logged-in user owns the requested object ID, attackers easily iterate through identifiers to read or modify private data records.
- ✗
Server-Side Request Forgery
Why it's wrong here
Server-Side Request Forgery occurs when a vulnerable application fetches a remote resource supplied by the user without adequate validation. Modifying a numerical user identifier in a RESTful API path is an access control failure, not an arbitrary outbound network request vulnerability originating from the backend server.
- ✗
Mass Assignment
Why it's wrong here
Mass Assignment happens when client-supplied inputs are automatically bound to internal object properties, potentially allowing privilege escalation or unwanted attribute modification. Manipulating a URL path parameter to access sequential resource records represents an authorization flaw rather than unintended data binding during object creation.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.