Courseiva
Web App API Attacks →mediumMultiple Choice

GCIH Web App API Attacks Practice Question

An incident responder is investigating a modern web application and notices that users can modify object identifiers in REST API endpoints to access sensitive records belonging to other tenants. Which primary vulnerability category does this represent?

⚠ Common exam trap

Candidates frequently confuse BOLA with Broken Object Property Level Authorization or traditional IDOR, failing to recognize that API-specific context emphasizes programmatic identifier enumeration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Broken Object Level Authorization

Broken Object Level Authorization occurs when an application fails to properly verify user permissions before granting access to objects based on the provided identifier. Attackers manipulate the ID parameter to view or modify unauthorized data, making this a critical Web App API security flaw requiring strict role-based checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-Site Request Forgery

    Why it's wrong here

    Cross-Site Request Forgery tricks a victim into executing unwanted actions on a trusted application where they are currently authenticated. It relies on session cookies rather than the direct manipulation of object identifiers within REST API query parameters or paths.

  • ✓

    Broken Object Level Authorization

    Why this is correct

    Modifying object identifiers to reach other tenants' records is Broken Object Level Authorization: the API authenticates the caller but never verifies that the caller owns the requested object. Authorization is enforced per object, not per endpoint, which is exactly the flaw described.

  • ✗

    Server-Side Request Forgery

    Why it's wrong here

    Server-Side Request Forgery involves tricking a server-side application into making HTTP requests to an arbitrary unintended domain or internal resource. It does not describe the direct parameter tampering used to access other users' database records.

  • ✗

    Mass Assignment Vulnerability

    Why it's wrong here

    Mass assignment occurs when an API binds client-supplied fields directly to object properties, allowing attackers to set attributes they should not control. Here the attacker alters an object identifier in the URL to reach another tenant's record, which is broken object level authorisation, not property-level binding.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.