Courseiva
Web App API Attacks →mediumMultiple Choice

GCIH Web App API Attacks Practice Question

An incident responder is investigating a RESTful API breach where an authenticated low-privileged user accessed administrative records by modifying an integer identifier in the resource path from /api/v1/users/104 to /api/v1/users/1. Which type of vulnerability has been exploited?

⚠ Common exam trap

Candidates frequently confuse Broken Object Level Authorization with Broken Function Level Authorization because both involve access control failures, but function authorization restricts administrative URLs rather than specific data record identifiers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Insecure Direct Object Reference

This scenario describes an Insecure Direct Object Reference vulnerability, commonly classified under Broken Object Level Authorization in modern API security taxonomies. The application fails to validate whether the requesting user possesses authorization to access the specific resource identifier requested in the URL path. Attackers systematically enumerate these predictable identifiers to harvest unauthorized sensitive data across multi-tenant API endpoints during security assessments and active breaches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Broken Function Level Authorization

    Why it's wrong here

    Broken function level authorisation concerns access to privileged operations or endpoints, such as reaching an admin-only action. This attacker stayed within the same users endpoint and altered the object identifier, so the flaw is object-level access control, not function-level. Function-level checks would matter if the path itself changed to an admin route.

  • ✗

    Cross-Site Request Forgery

    Why it's wrong here

    CSRF tricks a victim's authenticated browser into issuing unintended state-changing requests, relying on ambient session credentials. Here the attacker sent their own authenticated requests and simply changed an object identifier, which is an object-level authorisation failure, not request forgery. CSRF would fit a forged transfer or password change.

  • ✓

    Insecure Direct Object Reference

    Why this is correct

    The API trusted the client-supplied identifier without verifying that the authenticated user owned or was authorised for that record. Changing /users/104 to /users/1 returned another user's administrative data, which is the defining pattern of Insecure Direct Object Reference.

  • ✗

    Server-Side Request Forgery

    Why it's wrong here

    This flaw allows an attacker to induce the backend server to make HTTP requests to an arbitrary unintended external or internal destination, which is unrelated to modifying sequential user resource identifiers in an API path.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.