GCIH Web App Injection Attacks Practice Question
An organization discovers that an attacker executed operating system commands via a vulnerable web application endpoint. The application takes user input, constructs an XML payload, and passes it to an underlying XML parser without disabling external entity resolution. Which type of vulnerability enabled this command execution?
⚠ Common exam trap
Candidates often mistake this for 'Command Injection' because command execution occurs. However, the specific vector described is the parsing of XML entities, which defines it as XXE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
XML External Entity injection exploiting insecure XML parser configurations
XML External Entity (XXE) injection arises when applications parse untrusted XML input with external entity processing enabled. Attackers can define malicious entities referencing local system files, internal network resources, or command execution wrappers, leading to severe data compromise or remote code execution scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-Side Template Injection via malicious expressions evaluated by template engines
Why it's wrong here
Server-Side Template Injection occurs when user input is embedded unsafely into template engines like Jinja2 or Twig. This differs fundamentally from XML parsing flaws, as template injection evaluates server-side code constructs directly within view rendering logic.
- ✓
XML External Entity injection exploiting insecure XML parser configurations
Why this is correct
Failing to disable Document Type Definitions and external entity resolution in XML parsers allows attackers to read local files or trigger out-of-band requests. When combined with specific PHP wrappers, XXE can escalate into direct operating system command execution.
- ✗
Cross-Site Scripting via injected script tags within CDATA sections
Why it's wrong here
While XML documents can contain CDATA sections holding script content, rendering them improperly in a web browser leads to Cross-Site Scripting. Server-side command execution requires flaws in server processing logic rather than client-side script rendering issues.
- ✗
LDAP injection through improper attribute filtering in directory search queries
Why it's wrong here
LDAP injection targets directory search filters, not XML parsers, so it cannot explain external entity resolution or command execution here. It is tempting because both involve unsanitised input reaching an interpreter, but LDAP injection would be correct against a directory service querying attributes, not an XML parser.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.