GCIH · domain
Web App API Attacks
This GCIH domain covers attacks against web applications and APIs, including REST parameter tampering, IDOR, GraphQL abuse, and injection flaws. Questions test whether you can identify the failed security control, map the attack to the OWASP-style category, and choose the correct incident response action or documentation artifact.
Focused practice
Practice Web App API Attacks questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Web App API Attacks
Be able to read an API request, spot the modified identifier or query, and name the exact failed control (object-level authorization, not authentication). For GraphQL, identify missing depth or complexity limits as the cause of denial of service.
Identifying broken object level authorization (IDOR) when integer identifiers in REST paths or query parameters are modified
Recognizing GraphQL resource exhaustion from deeply nested or overly complex queries leading to denial of service
Selecting essential API security documentation components for incident responders, such as authentication schemes and endpoint inventories
Distinguishing authentication failures from authorization failures when a low-privileged user reaches administrative records
Watch out for
Common Web App API Attacks exam traps
- ▸Labeling IDOR as broken authentication; the user is authenticated, so the failure is authorization or access control at the object level.
- ▸Assuming input validation fixes IDOR; the fix is server-side authorization checks per object, not sanitizing the identifier.
- ▸Treating GraphQL depth attacks as injection; they are resource exhaustion or lack of query cost limiting, not code injection.
Question index
All Web App API Attacks questions (28)
Click any question to see the full explanation, or start a practice session above.
During a penetration test of a GraphQL API, an incident handler finds that the introspection system is enabled and can be queried without authentication. The handler retrieves the full schema, including hidden fields and mutations. What is the most significant security impact of this finding?
Medium2Refer to the exhibit. An attacker changes the 'final_price' to 0.00. What is the most likely vulnerability?
Hard3An incident responder is analyzing a web application that uses a REST API. The API accepts a 'file' parameter that specifies a URL from which to fetch an image. The responder observes that an attacker supplied a URL pointing to an internal metadata service (e.g., http://169.254.169.254/latest/meta-data/) and successfully retrieved sensitive instance credentials. Which vulnerability class does this represent?
Hard4In the context of API security, what does the 'Broken Object Level Authorization' (BOLA) vulnerability typically involve?
Medium5During a web application incident investigation, the SOC analyst discovers that an attacker sent a modified JSON payload containing an unexpected administrative attribute "is_admin": true during user registration, which successfully elevated the user's privileges. What vulnerability enabled this exploitation?
Medium6When analyzing a JSON Web Token (JWT) for potential security weaknesses in an API, which scenario indicates a 'None' algorithm attack is possible?
Hard7Which of the following is the most significant security risk associated with the use of 'API Keys' for authentication in modern cloud-native environments?
Medium8Which TWO methods are effective for mitigating Mass Assignment vulnerabilities in RESTful APIs?
Hard9An incident responder is investigating a modern web application and notices that users can modify object identifiers in REST API endpoints to access sensitive records belonging to other tenants. Which primary vulnerability category does this represent?
Medium10A GCIH incident handler is reviewing web server logs after a suspected API reconnaissance campaign. The logs show numerous requests to endpoints such as /api/v1/users, /api/v2/users, /api/v3/users, and /api/internal/users, all returning HTTP 404 except one. Which attack technique is most consistent with this pattern?
Medium11Which security measure is most effective against API-based Denial of Service (DoS) attacks targeted at resource-intensive endpoints?
Medium12During an incident response engagement, a GCIH analyst examines an API that accepts JSON input and notices that the application returns detailed database error messages when a single quote is inserted into the 'username' field. The analyst also observes that the same endpoint returns a 500 error when a specially crafted JSON object with nested arrays is submitted. Which vulnerability class is the analyst most likely investigating?
Hard13A security analyst is reviewing logs from a web application firewall (WAF) and notices a series of requests containing payloads like ' OR 1=1 --' and 'UNION SELECT username, password FROM users'. These requests are targeting the login endpoint. Which type of attack is being attempted?
Easy14An API uses OAuth 2.0. An attacker sends a request with a modified 'redirect_uri' parameter to an authorization endpoint. If successful, this could lead to which type of vulnerability?
Medium15An incident responder is examining a GraphQL API after a breach report. Query logs show a single POST to /graphql containing a query that requests a user's profile, that user's friends, each friend's friends, and so on through deeply chained relationship fields, all in one request. The response was several megabytes and the database showed a spike in joins. No authentication bypass occurred. Which attack does this describe?
Hard16Which THREE actions are recommended to secure APIs against Server-Side Request Forgery (SSRF)?
Hard17A GCIH candidate is reviewing a REST API that accepts XML in an upload endpoint used for importing supplier catalogs. During a purple-team exercise, testers want to demonstrate how XML-specific parser weaknesses could be abused against this endpoint. Which two techniques should the testers attempt to validate the parser's defenses? (Choose two.)
Medium18A GCIH analyst is called after a SaaS provider reports that an integration partner's API traffic began returning other tenants' records. The partner's client was calling /api/v3/documents/{documentId} and had recently started sending a second header, X-Tenant-Id, that the gateway trusts to route requests. The analyst confirms the partner is authenticated with a valid OAuth 2.0 bearer token scoped to its own tenant. Which weakness allowed the cross-tenant exposure?
Hard19During an incident involving a single-page application, a handler inspects a GraphQL endpoint at /graphql used for a customer portal. The handler captures a query that requests only the fields needed for a profile view, but the server response includes additional fields such as internalAccountTier, billingNotes, and ssnLastFour. The application uses a single shared GraphQL schema and no field-level authorization middleware. Which GraphQL-specific weakness is most directly demonstrated?
Hard20An incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?
Medium21An incident responder is investigating a RESTful API breach where an authenticated low-privileged user accessed administrative records by modifying an integer identifier in the resource path from /api/v1/users/104 to /api/v1/users/1. Which type of vulnerability has been exploited?
Medium22An incident responder is analyzing an API access log and notices a user with ID 104 is able to modify account settings for user ID 105 by simply changing the integer value in the URI endpoint from /api/v1/users/104/settings to /api/v1/users/105/settings without any additional token validation or role checks. Which specific OWASP API Security Top 10 vulnerability class does this scenario represent?
Medium23Which THREE items are essential components of an API security documentation strategy for incident responders?
Medium24A SOC analyst triages an alert showing that a mobile banking API responded to a request for /api/accounts/8842/transactions with HTTP 200 and another customer's transaction list. The requesting user was authenticated normally with a valid session token, but the account number in the URL belonged to a different customer. The API returned data without checking whether the authenticated user owned that account. Which vulnerability does this represent?
Easy25An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /api/v1/user/details?id=124. This vulnerability indicates a failure in which security control?
Medium26A GCIH analyst is examining a web application that uses GraphQL. The analyst notices that an attacker sent a deeply nested query that caused the server to consume excessive resources, leading to a denial of service. Which GraphQL-specific vulnerability is being exploited?
Medium27A GCIH incident responder is investigating a suspected API attack where an attacker manipulated a JSON Web Token (JWT) to gain unauthorized access. The responder needs to identify which two conditions would allow a JWT 'kid' (Key ID) header injection attack to succeed. (Choose two.)
Hard28An incident handler reviews web server logs from an e-commerce application and finds a burst of requests where the JSON body of a POST to /api/v2/orders/checkout contains a deeply nested object several thousand levels deep, causing the backend deserializer to exhaust CPU and memory until the worker crashes. The application accepts arbitrary JSON and binds it directly to internal model objects. Which vulnerability class best describes this attack?
MediumOther domains
All GCIH exam domains
Frequently asked questions
- What does the Web App API Attacks domain cover on the GCIH exam?
- Be able to read an API request, spot the modified identifier or query, and name the exact failed control (object-level authorization, not authentication). For GraphQL, identify missing depth or complexity limits as the cause of denial of service.
- How many questions are in this domain?
- This page lists all 28 Web App API Attacks questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Web App API Attacks questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.