Courseiva
Web App API Attacks →hardMultiple Choice

GCIH Web App API Attacks Practice Question

An incident responder is examining a GraphQL API after a breach report. Query logs show a single POST to /graphql containing a query that requests a user's profile, that user's friends, each friend's friends, and so on through deeply chained relationship fields, all in one request. The response was several megabytes and the database showed a spike in joins. No authentication bypass occurred. Which attack does this describe?

⚠ Common exam trap

The trap here is attributing any suspicious GraphQL request to introspection or alias batching, when the observed evidence is nested relationship traversal causing resource exhaustion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A resource-exhaustion query exploiting unbounded nesting of relationship fields

The request abused GraphQL's ability to traverse arbitrarily deep relationships in a single query, forcing the server to resolve a huge graph of related records and return a multi-megabyte response. Because the caller was authenticated, the weakness is missing query cost controls rather than an authentication flaw. Defenders should enforce depth limits, complexity scoring, pagination caps, and timeouts on the GraphQL layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A batched query attack using aliases to replay the same mutation many times

    Why it's wrong here

    Alias-based batching reuses one operation under many aliases to amplify a mutation or repeated lookup, and it typically shows as many aliases in a single document. The logged query instead traverses nested relationships to expand result volume, which is a depth and complexity problem rather than alias amplification, so batching does not describe what the responder observed.

  • ✗

    A server-side request forgery via a GraphQL resolver that fetches remote URLs

    Why it's wrong here

    SSRF through a resolver requires a field that accepts a URL and causes the server to fetch it, producing outbound traffic to attacker-chosen hosts. The evidence here is a large relational result set and increased database joins, with no indication of outbound fetches to external destinations, so the SSRF explanation does not fit the observed behavior.

  • ✓

    A resource-exhaustion query exploiting unbounded nesting of relationship fields

    Why this is correct

    The query chains relationship fields arbitrarily deep, so the server resolves a combinatorial explosion of related records in one request, producing a multi-megabyte response and heavy database joins. This is the GraphQL-specific resource exhaustion pattern that arises when depth, complexity, and pagination limits are absent. Authentication was valid, so the abuse is in query structure rather than identity, matching the observed database spike.

  • ✗

    GraphQL introspection abuse to map the schema

    Why it's wrong here

    Introspection queries ask the server to describe its schema, exposing types and fields that aid reconnaissance. The logged request does not request schema metadata; it walks real data relationships to pull records. While introspection may have preceded the attack, the resource-consuming request itself is a data-fetching abuse, so introspection is not the technique described by the observed query.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.