GCIH Web App API Attacks Practice Question
An incident responder is examining a GraphQL API after a breach report. Query logs show a single POST to /graphql containing a query that requests a user's profile, that user's friends, each friend's friends, and so on through deeply chained relationship fields, all in one request. The response was several megabytes and the database showed a spike in joins. No authentication bypass occurred. Which attack does this describe?
⚠ Common exam trap
The trap here is attributing any suspicious GraphQL request to introspection or alias batching, when the observed evidence is nested relationship traversal causing resource exhaustion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A resource-exhaustion query exploiting unbounded nesting of relationship fields
The request abused GraphQL's ability to traverse arbitrarily deep relationships in a single query, forcing the server to resolve a huge graph of related records and return a multi-megabyte response. Because the caller was authenticated, the weakness is missing query cost controls rather than an authentication flaw. Defenders should enforce depth limits, complexity scoring, pagination caps, and timeouts on the GraphQL layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A batched query attack using aliases to replay the same mutation many times
Why it's wrong here
Alias-based batching reuses one operation under many aliases to amplify a mutation or repeated lookup, and it typically shows as many aliases in a single document. The logged query instead traverses nested relationships to expand result volume, which is a depth and complexity problem rather than alias amplification, so batching does not describe what the responder observed.
- ✗
A server-side request forgery via a GraphQL resolver that fetches remote URLs
Why it's wrong here
SSRF through a resolver requires a field that accepts a URL and causes the server to fetch it, producing outbound traffic to attacker-chosen hosts. The evidence here is a large relational result set and increased database joins, with no indication of outbound fetches to external destinations, so the SSRF explanation does not fit the observed behavior.
- ✓
A resource-exhaustion query exploiting unbounded nesting of relationship fields
Why this is correct
The query chains relationship fields arbitrarily deep, so the server resolves a combinatorial explosion of related records in one request, producing a multi-megabyte response and heavy database joins. This is the GraphQL-specific resource exhaustion pattern that arises when depth, complexity, and pagination limits are absent. Authentication was valid, so the abuse is in query structure rather than identity, matching the observed database spike.
- ✗
GraphQL introspection abuse to map the schema
Why it's wrong here
Introspection queries ask the server to describe its schema, exposing types and fields that aid reconnaissance. The logged request does not request schema metadata; it walks real data relationships to pull records. While introspection may have preceded the attack, the resource-consuming request itself is a data-fetching abuse, so introspection is not the technique described by the observed query.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.