GCIH Web App API Attacks Practice Question
An incident responder is analyzing a web application that uses a REST API. The API accepts a 'file' parameter that specifies a URL from which to fetch an image. The responder observes that an attacker supplied a URL pointing to an internal metadata service (e.g., http://169.254.169.254/latest/meta-data/) and successfully retrieved sensitive instance credentials. Which vulnerability class does this represent?
⚠ Common exam trap
It's easy for candidates to confuse SSRF with CSRF or XXE, but the key differentiator is the server making a request to an internal resource based on user-supplied URL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server-Side Request Forgery (SSRF)
The server fetched a user-supplied URL, which pointed to an internal metadata service, and returned sensitive credentials. This is a Server-Side Request Forgery (SSRF) attack, where the attacker abuses the server's ability to make requests to internal resources. The other options describe different attack vectors that do not involve the server making arbitrary outbound requests based on user input. SSRF is the correct classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Insecure Direct Object Reference (IDOR)
Why it's wrong here
IDOR involves accessing objects by manipulating identifiers, such as changing a user ID in a URL. In this case, the attacker is not manipulating an object identifier but supplying a URL to an internal service. The server's action of fetching that URL is the core issue. IDOR does not involve server-side requests to arbitrary URLs. Hence, this option is not applicable.
- ✗
Cross-Site Request Forgery (CSRF)
Why it's wrong here
CSRF involves tricking a victim's browser into sending an authenticated request to a vulnerable application. Here, the attacker directly supplies a URL to the API, and the server fetches it; there is no victim browser or forged request from a trusted user. CSRF does not involve server-side fetching of remote resources. Therefore, this option is incorrect for the described scenario.
- ✓
Server-Side Request Forgery (SSRF)
Why this is correct
SSRF occurs when an application fetches a remote resource without validating the user-supplied URL, allowing attackers to make requests to internal systems. In this scenario, the attacker supplied a URL to the cloud metadata service, and the server fetched it, exposing credentials. This is a classic SSRF exploitation. The other options do not match the behavior of the server making a request to an attacker-controlled or internal URL.
- ✗
XML External Entity (XXE) injection
Why it's wrong here
XXE occurs when an application parses XML input containing external entities, leading to file disclosure or SSRF. However, the scenario describes a JSON or form parameter specifying a URL, not XML parsing. There is no mention of XML input. XXE is a different vulnerability class that requires XML processing. Thus, this option does not fit the observed behavior.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.