Courseiva

CCNA Web App API Attacks Questions

28 questions · Web App API Attacks · All types, answers revealed

1
MCQmedium

During a penetration test of a GraphQL API, an incident handler finds that the introspection system is enabled and can be queried without authentication. The handler retrieves the full schema, including hidden fields and mutations. What is the most significant security impact of this finding?

A.Attackers can directly execute arbitrary code on the GraphQL server through introspection queries.
B.Attackers can bypass authentication by sending a specially crafted introspection query that returns valid session tokens.
C.Attackers can cause a denial of service by sending an introspection query that recursively expands the schema indefinitely.
D.Attackers can map the entire API surface, identify sensitive fields and mutations, and craft targeted queries to abuse them.
AnswerD

Introspection reveals types, fields, arguments, and mutations, giving attackers a complete blueprint of the API. This enables precise targeting of sensitive operations, such as user data retrieval or privilege escalation via mutations. The exposure significantly reduces the effort needed for further attacks, making it a serious information disclosure issue. This is the primary risk when introspection is left enabled without authentication.

Why this answer

Exposed GraphQL introspection lets attackers retrieve the full schema, including hidden fields and mutations. This information disclosure enables them to craft precise queries and mutations that target sensitive operations, significantly lowering the effort required for further exploitation. The other options either misstate the technical effect or focus on less likely outcomes.

Therefore, schema mapping and targeted abuse is the most significant impact.

Exam trap

The trap here is assuming introspection directly leads to code execution or authentication bypass, when it primarily enables reconnaissance and targeted attacks.

2
MCQhard

Refer to the exhibit. An attacker changes the 'final_price' to 0.00. What is the most likely vulnerability?

A.Broken Object Level Authorization
B.Mass Assignment
C.Command Injection
D.Cross-Site Scripting
AnswerB

The API allows the client to overwrite the 'final_price' attribute, which should be a server-calculated value. This is a classic Mass Assignment flaw where the application layer blindly binds user-supplied JSON properties directly to the backend object model, allowing the attacker to alter critical business logic.

Why this answer

The exhibit shows a Mass Assignment vulnerability. The API accepts the client-provided 'final_price' instead of calculating it server-side. By exposing internal fields that should be read-only or calculated internally, the API allows the client to influence business logic.

In this case, the attacker successfully manipulated the payment amount, demonstrating why sensitive fields must be protected from external modification during request binding processes in the API backend.

Exam trap

Exam takers often guess authorization failures like IDOR or BOLA, missing that altering monetary amounts or pricing fields via input submission points to Mass Assignment.

3
MCQhard

An incident responder is analyzing a web application that uses a REST API. The API accepts a 'file' parameter that specifies a URL from which to fetch an image. The responder observes that an attacker supplied a URL pointing to an internal metadata service (e.g., http://169.254.169.254/latest/meta-data/) and successfully retrieved sensitive instance credentials. Which vulnerability class does this represent?

A.Insecure Direct Object Reference (IDOR)
B.Cross-Site Request Forgery (CSRF)
C.Server-Side Request Forgery (SSRF)
D.XML External Entity (XXE) injection
AnswerC

SSRF occurs when an application fetches a remote resource without validating the user-supplied URL, allowing attackers to make requests to internal systems. In this scenario, the attacker supplied a URL to the cloud metadata service, and the server fetched it, exposing credentials. This is a classic SSRF exploitation. The other options do not match the behavior of the server making a request to an attacker-controlled or internal URL.

Why this answer

The server fetched a user-supplied URL, which pointed to an internal metadata service, and returned sensitive credentials. This is a Server-Side Request Forgery (SSRF) attack, where the attacker abuses the server's ability to make requests to internal resources. The other options describe different attack vectors that do not involve the server making arbitrary outbound requests based on user input.

SSRF is the correct classification.

Exam trap

The trap here is confusing SSRF with CSRF or XXE, but the key differentiator is the server making a request to an internal resource based on user-supplied URL.

4
MCQmedium

In the context of API security, what does the 'Broken Object Level Authorization' (BOLA) vulnerability typically involve?

A.Failure to encrypt sensitive API parameters
B.Inability to verify the requester's identity
C.Lack of authorization checks on object access
D.Excessive use of third-party API libraries
AnswerC

BOLA occurs when an application relies on user-provided input to identify an object but fails to verify that the authenticated user actually has the permissions to access that specific object. This enables attackers to interact with resources belonging to other users simply by changing identifiers.

Why this answer

BOLA occurs when an API endpoint uses user-supplied input to access a resource (like a database ID) but fails to check if the requester is authorized to access that specific object. Because APIs often expose internal resource IDs directly, attackers can easily enumerate or modify these IDs to access other users' data, making this one of the most common and damaging vulnerabilities in modern web and mobile API architectures.

Exam trap

Test-takers often confuse BOLA with Broken Function Level Authorization, failing to differentiate between user-level object access and administrative function-level restrictions.

5
MCQmedium

During a web application incident investigation, the SOC analyst discovers that an attacker sent a modified JSON payload containing an unexpected administrative attribute "is_admin": true during user registration, which successfully elevated the user's privileges. What vulnerability enabled this exploitation?

A.Broken User Authentication
B.Server-Side Request Forgery
C.Mass Assignment
D.Cross-Site Scripting
AnswerC

Mass assignment arises when automated object mapping features bind HTTP request parameters directly to internal data structure properties. Attackers exploit this by appending sensitive fields like role or status flags to registration or profile update payloads to gain unauthorized administrative privileges.

Why this answer

Mass assignment occurs when frameworks automatically bind user input parameters directly to backend data models without proper filtering. This allows attackers to inject privileged fields that were never intended to be exposed during client-side registration forms. GCIH handlers must trace data binding configurations and ensure explicit allowlisting of updatable attributes to prevent privilege escalation incidents via API request tampering.

Exam trap

Candidates often misidentify this as 'Broken Object Level Authorization' (BOLA). While related to privilege, 'Mass Assignment' specifically refers to the binding of unexpected user input to internal object attributes.

6
MCQhard

When analyzing a JSON Web Token (JWT) for potential security weaknesses in an API, which scenario indicates a 'None' algorithm attack is possible?

A.The token expires in less than 60 seconds
B.The header contains 'alg': 'none'
C.The token uses RS256 instead of HS256
D.The secret key is stored in an environment variable
AnswerB

If the 'alg' header is set to 'none', the token is effectively unsigned. If the API implementation is vulnerable, it will trust the payload without requiring a cryptographic signature, allowing attackers to forge arbitrary tokens by modifying the payload content to elevate privileges or impersonate other users.

Why this answer

A 'None' algorithm attack occurs when the JWT header specifies 'alg': 'none'. If the API backend fails to strictly validate the algorithm field and accepts this header, it treats the token as unsigned. An attacker can then modify the payload (e.g., changing 'user_id' to 'admin') and submit the token without a valid cryptographic signature, effectively bypassing authentication controls because the backend skips signature verification for 'none' algorithms.

Exam trap

Candidates frequently look for weak secrets or expired tokens, overlooking the explicit algorithmic header directive that allows the server to bypass signature verification entirely.

7
MCQmedium

Which of the following is the most significant security risk associated with the use of 'API Keys' for authentication in modern cloud-native environments?

A.They are easily cracked using brute-force tools
B.They cannot be used over HTTPS connections
C.They are static secrets prone to leakage
D.They are incompatible with RESTful architecture
AnswerC

API keys are long-lived static secrets that often appear in source code, configuration files, or logs. Since they typically grant permanent access until revoked, their leakage represents a high risk, as attackers can use the stolen keys indefinitely without needing to re-authenticate or renew session tokens.

Why this answer

API keys are often static and long-lived, making them highly susceptible to theft through code repository leaks, log exposure, or interception. Once stolen, they are difficult to rotate and often grant broad access. Unlike short-lived tokens like OAuth access tokens, static keys lack expiration, context, and granular scope, creating a significant security burden for organizations that fail to implement strict rotation and revocation procedures for their distributed keys.

Exam trap

Candidates often focus on 'lack of encryption' or 'weak hashing'. These are secondary concerns; the primary systemic risk of API keys is their static, long-lived nature that makes them permanent secrets.

8
MCQhard

Which TWO methods are effective for mitigating Mass Assignment vulnerabilities in RESTful APIs?

A.Implement strict input allow-lists for model binding
B.Use Data Transfer Objects (DTOs) for input mapping
C.Always sanitize input for SQL injection patterns
D.Increase the complexity of the API authentication token
E.Disable all write operations on public API endpoints
AnswerA, B

Defining an explicit allow-list of fields that the API is permitted to bind ensures that unexpected or sensitive fields provided by the client are ignored. This technique creates a secure boundary between external input and internal object properties, effectively neutralizing Mass Assignment risks.

Why this answer

Mass Assignment occurs when an API endpoint automatically binds client-provided input to internal data models or database fields without explicit filtering. By using Data Transfer Objects (DTOs) or explicit allow-lists, developers ensure only intended fields are updated. This prevents attackers from overwriting sensitive fields like 'is_admin' or 'account_balance' that should not be exposed to user modification during standard API update operations.

Exam trap

Students often mistakenly select output encoding or parameterized queries, confusing Mass Assignment (an input binding issue during writes) with SQL injection or Cross-Site Scripting vulnerabilities.

9
MCQmedium

An incident responder is investigating a modern web application and notices that users can modify object identifiers in REST API endpoints to access sensitive records belonging to other tenants. Which primary vulnerability category does this represent?

A.Cross-Site Request Forgery
B.Broken Object Level Authorization
C.Server-Side Request Forgery
D.Mass Assignment Vulnerability
AnswerB

Modifying object identifiers to reach other tenants' records is Broken Object Level Authorization: the API authenticates the caller but never verifies that the caller owns the requested object. Authorization is enforced per object, not per endpoint, which is exactly the flaw described.

Why this answer

Broken Object Level Authorization occurs when an application fails to properly verify user permissions before granting access to objects based on the provided identifier. Attackers manipulate the ID parameter to view or modify unauthorized data, making this a critical Web App API security flaw requiring strict role-based checks.

Exam trap

Candidates frequently confuse BOLA with Broken Object Property Level Authorization or traditional IDOR, failing to recognize that API-specific context emphasizes programmatic identifier enumeration.

10
MCQmedium

A GCIH incident handler is reviewing web server logs after a suspected API reconnaissance campaign. The logs show numerous requests to endpoints such as /api/v1/users, /api/v2/users, /api/v3/users, and /api/internal/users, all returning HTTP 404 except one. Which attack technique is most consistent with this pattern?

A.Cross-site scripting (XSS) in API responses
B.API version enumeration
C.Server-side request forgery (SSRF) via API parameters
D.JWT algorithm confusion attack
AnswerB

The attacker systematically probes multiple API version prefixes and internal paths to discover which versions are live and may lack security controls. The single successful response reveals a valid version, making version enumeration the technique in use. This is a common precursor to exploiting deprecated or unpatched API versions.

Why this answer

The pattern of requests to multiple API version prefixes and internal-looking paths, with only one returning a non-404 response, indicates deliberate version and endpoint enumeration. Attackers use this to map the API surface and find versions that may be deprecated, unpatched, or less protected, which then become targets for further exploitation.

Exam trap

The trap here is assuming that repeated 404 responses indicate a failed attack, when in fact they are the expected outcome of enumeration that successfully identifies a valid API version.

11
MCQmedium

Which security measure is most effective against API-based Denial of Service (DoS) attacks targeted at resource-intensive endpoints?

A.Enforcing HTTPS for all traffic
B.Implementing robust rate limiting
C.Using JWTs for authentication
D.Disabling CORS headers
AnswerB

Rate limiting restricts the frequency of requests from a specific source, preventing attackers from overloading the API with resource-intensive requests. This ensures that system resources are distributed fairly and prevents any single source from exhausting the server's capacity, which is the primary goal of API DoS prevention.

Why this answer

Rate limiting is the standard defense against resource exhaustion in APIs. By enforcing limits on the number of requests a client can make within a specific timeframe, the API prevents a single user or bot from monopolizing backend CPU, memory, or database connections. This ensures that the service remains available to other legitimate users, mitigating the risk of intentional or accidental system degradation caused by heavy API consumption patterns.

Exam trap

Candidates frequently choose 'Web Application Firewalls' (WAF). While WAFs assist, rate limiting is the specific, most effective architectural control for preventing resource exhaustion at the API endpoint level itself.

12
MCQhard

During an incident response engagement, a GCIH analyst examines an API that accepts JSON input and notices that the application returns detailed database error messages when a single quote is inserted into the 'username' field. The analyst also observes that the same endpoint returns a 500 error when a specially crafted JSON object with nested arrays is submitted. Which vulnerability class is the analyst most likely investigating?

A.Insecure direct object references (IDOR)
B.Excessive data exposure in API responses
C.Injection flaws, such as SQL injection and improper input validation
D.Broken authentication via weak API keys
AnswerC

Detailed database errors on quote injection strongly suggest SQL injection, while the 500 error on malformed nested JSON indicates insufficient input validation. Together, they point to injection flaws where untrusted input reaches interpreters or parsers. This is consistent with the analyst's observations and is a high-severity finding.

Why this answer

The combination of database error messages in response to a single quote and a 500 error from malformed nested JSON indicates that the application is not properly validating or sanitizing input before passing it to backend interpreters. This is a classic sign of injection flaws, which can lead to data compromise or remote code execution.

Exam trap

The trap here is focusing on the 500 error as a simple crash rather than recognizing it as a symptom of improper input validation that often accompanies injection vulnerabilities.

13
MCQeasy

A security analyst is reviewing logs from a web application firewall (WAF) and notices a series of requests containing payloads like ' OR 1=1 --' and 'UNION SELECT username, password FROM users'. These requests are targeting the login endpoint. Which type of attack is being attempted?

A.Cross-Site Request Forgery (CSRF)
B.Cross-Site Scripting (XSS)
C.SQL Injection (SQLi)
D.Command Injection
AnswerC

The payloads ' OR 1=1 --' and 'UNION SELECT ...' are classic SQL injection attempts. They aim to alter the logic of SQL queries to bypass authentication or extract data. The login endpoint is a common target for such attacks. This matches the observed behavior, making SQL injection the correct classification. The other options describe different attack types that do not involve SQL syntax.

Why this answer

The payloads contain SQL keywords and syntax designed to alter database queries, such as bypassing authentication or extracting data via UNION. This is characteristic of SQL injection. The other options represent different attack categories: XSS targets client-side scripts, command injection targets OS commands, and CSRF targets user browsers.

The evidence clearly points to SQL injection.

Exam trap

The trap here is misclassifying SQL injection as command injection because both are injection attacks, but the payload syntax clearly indicates SQL.

14
MCQmedium

An API uses OAuth 2.0. An attacker sends a request with a modified 'redirect_uri' parameter to an authorization endpoint. If successful, this could lead to which type of vulnerability?

A.Denial of Service
B.Cross-Site Request Forgery
C.Authorization Code Interception
D.Server-Side Request Forgery
AnswerC

By modifying the redirect_uri to an attacker-controlled endpoint, the authorization server redirects the user's browser with the authorization code sent to the attacker. The attacker then exchanges this code for a valid access token, bypassing standard authentication flows and gaining full access to the victim's account.

Why this answer

Manipulating the 'redirect_uri' in an OAuth flow is a classic technique to facilitate Authorization Code Interception. By changing the URI to a domain under the attacker's control, the attacker can cause the authorization server to send the sensitive authorization code to them instead of the legitimate client application, enabling them to exchange the code for an access token and impersonate the user.

Exam trap

Students often select generic Cross-Site Request Forgery (CSRF) instead of the specific OAuth attack vector involving authorization code interception via redirect URI manipulation.

15
MCQhard

An incident responder is examining a GraphQL API after a breach report. Query logs show a single POST to /graphql containing a query that requests a user's profile, that user's friends, each friend's friends, and so on through deeply chained relationship fields, all in one request. The response was several megabytes and the database showed a spike in joins. No authentication bypass occurred. Which attack does this describe?

A.A batched query attack using aliases to replay the same mutation many times
B.A server-side request forgery via a GraphQL resolver that fetches remote URLs
C.A resource-exhaustion query exploiting unbounded nesting of relationship fields
D.GraphQL introspection abuse to map the schema
AnswerC

The query chains relationship fields arbitrarily deep, so the server resolves a combinatorial explosion of related records in one request, producing a multi-megabyte response and heavy database joins. This is the GraphQL-specific resource exhaustion pattern that arises when depth, complexity, and pagination limits are absent. Authentication was valid, so the abuse is in query structure rather than identity, matching the observed database spike.

Why this answer

The request abused GraphQL's ability to traverse arbitrarily deep relationships in a single query, forcing the server to resolve a huge graph of related records and return a multi-megabyte response. Because the caller was authenticated, the weakness is missing query cost controls rather than an authentication flaw. Defenders should enforce depth limits, complexity scoring, pagination caps, and timeouts on the GraphQL layer.

Exam trap

The trap here is attributing any suspicious GraphQL request to introspection or alias batching, when the observed evidence is nested relationship traversal causing resource exhaustion.

16
MCQhard

Which THREE actions are recommended to secure APIs against Server-Side Request Forgery (SSRF)?

A.Implement a strict allow-list for URLs
B.Disable unused URI schemes like file:// or gopher://
C.Network-level segmentation of the API server
D.Use a public proxy for all outgoing requests
E.Store all API secrets in the URL parameters
AnswerA, B, C

Allow-lists ensure the API server only makes requests to trusted, predefined domains. By rejecting requests to unexpected or internal endpoints, the risk of the server being used as a proxy to attack internal infrastructure is significantly reduced, effectively mitigating the primary target of most SSRF exploits.

Why this answer

SSRF occurs when an API is tricked into making requests to internal or unauthorized external resources. To prevent this, developers must use strict allow-lists for destination domains, disable unused URL schemes (like file://), and enforce network-level segmentation that restricts the API server's ability to reach internal management interfaces or metadata services. These layers of defense ensure that even if an input parameter is compromised, the server remains isolated from critical internal assets.

Exam trap

Candidates often select client-side validation techniques or general firewall rules, forgetting that SSRF requires server-side restrictions like URL allow-lists and network segmentation.

17
Multi-Selectmedium

A GCIH candidate is reviewing a REST API that accepts XML in an upload endpoint used for importing supplier catalogs. During a purple-team exercise, testers want to demonstrate how XML-specific parser weaknesses could be abused against this endpoint. Which two techniques should the testers attempt to validate the parser's defenses? (Choose two.)

Select 2 answers
A.Upload an oversized multipart file to exhaust disk space on the API host
B.Inject a SQL UNION statement into the catalog name field to test database query construction
C.Submit an XML document with an entity definition that recursively references itself to test for exponential entity expansion
D.Send a JSON body with a million nested arrays to the same endpoint to test depth limits
E.Submit an XML document containing an external entity declaration that references a local file path to test for XML External Entity processing
AnswersC, E

Recursive entity definitions cause parsers to expand references exponentially, the classic billion-laughs pattern that consumes memory and CPU. Testing this against the catalog import shows whether the parser enforces entity expansion limits or disables internal entity resolution. It is XML-specific and directly relevant to an upload endpoint that must safely handle documents from external suppliers.

Why this answer

Both selected techniques exercise the XML parser itself rather than the surrounding application logic. External entity declarations reveal whether the parser resolves references to local files or network resources, while recursive entity definitions reveal whether expansion is bounded. Together they validate the two most impactful XML-specific defenses for an endpoint that must accept documents from untrusted suppliers.

Exam trap

The trap here is choosing generic input-validation tests like SQL injection or oversized uploads instead of techniques that specifically exercise XML entity handling.

18
MCQhard

A GCIH analyst is called after a SaaS provider reports that an integration partner's API traffic began returning other tenants' records. The partner's client was calling /api/v3/documents/{documentId} and had recently started sending a second header, X-Tenant-Id, that the gateway trusts to route requests. The analyst confirms the partner is authenticated with a valid OAuth 2.0 bearer token scoped to its own tenant. Which weakness allowed the cross-tenant exposure?

A.The document IDs were sequential integers, allowing enumeration of other tenants' records by incrementing the identifier
B.The OAuth 2.0 bearer token was forged because the partner guessed the signing key used by the authorization server
C.The integration partner exploited a race condition in the API's caching layer to retrieve stale responses belonging to other tenants
D.The API trusted a client-supplied header for tenant routing instead of deriving tenant scope from the authenticated token claims
AnswerD

Because the gateway routes on the attacker-controllable X-Tenant-Id header while authorization relies only on the bearer token, an authenticated partner can name any tenant and receive its documents. The tenant boundary should be derived from a verified token claim or server-side session, never from a header the caller can set. This is a broken authorization design flaw rather than a token forgery or injection issue.

Why this answer

The gateway trusted an attacker-controllable header to decide which tenant's data to return while authorization relied solely on the caller's own bearer token. Because tenant selection and authorization were decoupled, any authenticated caller could request another tenant's documents by naming that tenant in the header. The fix is to derive tenant scope from verified token claims or server-side state and ignore client-supplied routing headers for authorization decisions.

Exam trap

The trap here is focusing on token validity or ID enumeration while missing that a client-controlled routing header silently overrode the tenant boundary.

19
MCQhard

During an incident involving a single-page application, a handler inspects a GraphQL endpoint at /graphql used for a customer portal. The handler captures a query that requests only the fields needed for a profile view, but the server response includes additional fields such as internalAccountTier, billingNotes, and ssnLastFour. The application uses a single shared GraphQL schema and no field-level authorization middleware. Which GraphQL-specific weakness is most directly demonstrated?

A.GraphQL aliasing used to perform a denial-of-service attack
B.Excessive data exposure from over-fetching sensitive fields in the GraphQL response
C.GraphQL query batching used to bypass rate limits
D.GraphQL introspection enabled on the production endpoint
AnswerB

The endpoint returns sensitive fields that the client query did not request, and no field-level authorization prevents them from being serialized. In GraphQL, the server executes resolvers for fields selected by the query, but if a resolver or schema design includes sensitive properties in the returned object, the response can expose them. The handler should treat this as excessive data exposure and review resolver authorization and field visibility.

Why this answer

The response includes sensitive fields that the client did not request, and the server lacks field-level authorization to prevent their serialization. GraphQL resolvers return object properties according to schema and resolver logic, so sensitive data can leak even when the query appears minimal. The handler should focus on excessive data exposure and recommend field-level authorization, schema review, and response filtering.

Exam trap

The trap here is assuming that because the client requested only a few fields, the server cannot return more; in GraphQL, resolver output and schema design determine what is serialized, so over-fetching can expose sensitive data.

20
MCQmedium

An incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?

A.Cross-Site Request Forgery
B.Broken Object Level Authorization
C.Server-Side Request Forgery
D.Mass Assignment
AnswerB

APIs frequently expose endpoints that handle object identifiers, creating a wide attack surface for object-level access control flaws. Without proper authorization validation verifying whether the logged-in user owns the requested object ID, attackers easily iterate through identifiers to read or modify private data records.

Why this answer

This scenario clearly demonstrates Broken Object Level Authorization, where authorization validation is missing in the object identifier tier. Attackers exploit this design flaw to harvest unauthorized records horizontally or vertically. Incident handlers must recognize API1:2023 risks during web application forensics to properly scope data exfiltration incidents and remediate flawed access control logic across microservices.

Exam trap

Test-takers often mix up BOLA and IDOR or confuse them with broken function-level authorization, overlooking that resource-specific object manipulation points squarely to object-level flaws.

21
MCQmedium

An incident responder is investigating a RESTful API breach where an authenticated low-privileged user accessed administrative records by modifying an integer identifier in the resource path from /api/v1/users/104 to /api/v1/users/1. Which type of vulnerability has been exploited?

A.Broken Function Level Authorization
B.Cross-Site Request Forgery
C.Insecure Direct Object Reference
D.Server-Side Request Forgery
AnswerC

The API trusted the client-supplied identifier without verifying that the authenticated user owned or was authorised for that record. Changing /users/104 to /users/1 returned another user's administrative data, which is the defining pattern of Insecure Direct Object Reference.

Why this answer

This scenario describes an Insecure Direct Object Reference vulnerability, commonly classified under Broken Object Level Authorization in modern API security taxonomies. The application fails to validate whether the requesting user possesses authorization to access the specific resource identifier requested in the URL path. Attackers systematically enumerate these predictable identifiers to harvest unauthorized sensitive data across multi-tenant API endpoints during security assessments and active breaches.

Exam trap

Candidates frequently confuse Broken Object Level Authorization with Broken Function Level Authorization because both involve access control failures, but function authorization restricts administrative URLs rather than specific data record identifiers.

22
MCQmedium

An incident responder is analyzing an API access log and notices a user with ID 104 is able to modify account settings for user ID 105 by simply changing the integer value in the URI endpoint from /api/v1/users/104/settings to /api/v1/users/105/settings without any additional token validation or role checks. Which specific OWASP API Security Top 10 vulnerability class does this scenario represent?

A.Broken Authentication due to weak session token generation algorithms allowing session hijacking across user accounts.
B.Broken Object Level Authorization resulting from missing access control validation checks on resource identifiers embedded directly within API request paths.
C.Mass Assignment vulnerability caused by automatically binding incoming HTTP request parameters to internal backend database object properties.
D.Improper Assets Management stemming from exposed documentation and forgotten non-production API endpoints lacking proper security controls.
AnswerB

Missing authorization checks on resource identifiers allow authenticated users to access or modify objects by altering parameters like user IDs in the URI. This represents a classic failure of object-level access controls within modern RESTful API architectures.

Why this answer

This scenario describes Broken Object Level Authorization, where an API endpoint fails to verify whether the authenticated user possesses the appropriate permissions to access or modify a specific object identifier within the URI. Attackers exploit this design flaw to systematically harvest or alter sensitive data across multiple accounts. Recognizing this architectural failure is vital for incident handlers performing root-cause analysis during data breach investigations involving web applications and modern API microservices.

Exam trap

Candidates frequently confuse this with Broken Authentication because the attack involves user identifiers, but the core issue is the complete lack of authorization checks once the user is already authenticated.

23
MCQmedium

Which THREE items are essential components of an API security documentation strategy for incident responders?

A.Up-to-date OpenAPI/Swagger specifications
B.Complete inventory of all exposed API endpoints
C.Detailed API rate-limiting and throttling policies
D.Hardcoded database credentials for internal services
E.Customer personal identifiable information (PII) logs
AnswerA, B, C

OpenAPI documents provide a ground truth of the API's intended design, including expected input formats, authentication methods, and endpoint definitions. Responders use this to detect anomalies by comparing actual request structures against the documented schema to identify malicious variations or unexpected inputs.

Why this answer

Effective incident response for APIs requires comprehensive documentation. API specifications (like OpenAPI/Swagger) provide the baseline for expected behavior and valid endpoints. Inventory documentation ensures all endpoints are known and monitored.

Finally, security headers and rate-limiting policies document the defense-in-depth posture. Without these, responders cannot differentiate between legitimate traffic patterns and malicious exploitation attempts during an active security event or during post-incident forensic analysis.

Exam trap

Candidates often select 'API keys' or 'authentication logs' as essential components. While useful, they are not structural documentation strategies required for incident responders to understand API behavior and baseline traffic patterns during an active event.

24
MCQeasy

A SOC analyst triages an alert showing that a mobile banking API responded to a request for /api/accounts/8842/transactions with HTTP 200 and another customer's transaction list. The requesting user was authenticated normally with a valid session token, but the account number in the URL belonged to a different customer. The API returned data without checking whether the authenticated user owned that account. Which vulnerability does this represent?

A.Broken object level authorization on the account resource
B.Cross-site request forgery against the transactions endpoint
C.Server-side request forgery through the account identifier parameter
D.Insecure direct object reference in the session token generation
AnswerA

The API authenticated the caller but never verified that the caller owned account 8842 before returning its transactions, which is the defining characteristic of broken object level authorization. Access control must be enforced per object on every request using the authenticated identity, not merely by requiring a valid session. This is why a legitimate user can read another customer's financial records simply by changing the identifier.

Why this answer

The caller was properly authenticated, but the API failed to confirm that the authenticated identity owned the account referenced in the URL. Authorization must be evaluated per object on every request, comparing the resource's owner against the caller's identity. Relying on a valid session alone creates exactly this exposure, where changing an identifier yields another customer's data.

Exam trap

The trap here is treating a valid authenticated session as sufficient authorization, when the missing ownership check on the object is the actual flaw.

25
MCQmedium

An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /api/v1/user/details?id=124. This vulnerability indicates a failure in which security control?

A.Broken Authentication
B.Insecure Direct Object Reference
C.Cross-Site Scripting
D.Insufficient Logging and Monitoring
AnswerB

IDOR occurs when an application provides direct access to objects based on user-supplied input. By manipulating the ID parameter, the attacker accesses unauthorized data records. APIs are particularly susceptible to this when they rely on sequential IDs for object retrieval without verifying user permissions.

Why this answer

This scenario describes Insecure Direct Object Reference (IDOR). The application fails to verify if the authenticated user has authorization to access the object associated with the ID parameter. In API security, this is a critical flaw because APIs often expose backend database keys directly.

Proper mitigation requires server-side access control checks on every request, ensuring the requester owns the resource before returning sensitive data.

Exam trap

Candidates sometimes misidentify this as a broken authentication issue or API parameter tampering, missing that direct reference to database keys via predictable parameters defines IDOR.

26
MCQmedium

A GCIH analyst is examining a web application that uses GraphQL. The analyst notices that an attacker sent a deeply nested query that caused the server to consume excessive resources, leading to a denial of service. Which GraphQL-specific vulnerability is being exploited?

A.GraphQL query depth attack
B.GraphQL alias overloading
C.GraphQL batching attack
D.GraphQL introspection abuse
AnswerA

GraphQL allows clients to request nested fields, and without depth limiting, an attacker can craft a query with many levels of nesting. This can cause exponential resource consumption as the server resolves each level, leading to denial of service. This is known as a query depth attack.

Why this answer

GraphQL's flexible query language allows clients to specify nested fields. Without proper limits, an attacker can send a query with excessive depth, causing the server to recursively resolve many levels and exhaust CPU or memory. This is a query depth attack, a common GraphQL-specific denial-of-service vector.

Exam trap

The trap here is assuming that any resource exhaustion in GraphQL is due to batching or aliases, when the specific indicator—deep nesting—points to a query depth attack.

27
Multi-Selecthard

A GCIH incident responder is investigating a suspected API attack where an attacker manipulated a JSON Web Token (JWT) to gain unauthorized access. The responder needs to identify which two conditions would allow a JWT 'kid' (Key ID) header injection attack to succeed. (Choose two.)

Select 2 answers
A.The application uses a symmetric signing algorithm and the secret is weak or guessable.
B.The application allows the 'kid' header to specify an absolute path or URL that the server will fetch to obtain the key.
C.The application uses the 'kid' value to construct a file path for retrieving the verification key without proper sanitization.
D.The JWT is transmitted over an unencrypted HTTP connection, allowing token interception.
E.The application supports the 'none' algorithm and accepts unsigned tokens.
AnswersB, C

If the server fetches the key from a location specified by the 'kid' header, an attacker can point it to a malicious server hosting a key they control, or to a local file. This allows the attacker to sign tokens with a key the server will trust, bypassing authentication.

Why this answer

JWT 'kid' injection succeeds when the application uses the 'kid' header to determine the verification key without validating its content. If the 'kid' is used to build a file path or fetch a remote key, an attacker can manipulate it to use a key they control, forging valid tokens. The other conditions describe different JWT weaknesses.

Exam trap

The trap here is conflating 'kid' injection with other JWT attacks like 'none' algorithm or weak secret, which require different conditions and do not involve the 'kid' header.

28
MCQmedium

An incident handler reviews web server logs from an e-commerce application and finds a burst of requests where the JSON body of a POST to /api/v2/orders/checkout contains a deeply nested object several thousand levels deep, causing the backend deserializer to exhaust CPU and memory until the worker crashes. The application accepts arbitrary JSON and binds it directly to internal model objects. Which vulnerability class best describes this attack?

A.Mass assignment through the checkout JSON binding
B.Injection through unvalidated JSON string values
C.Server-side request forgery triggered by the checkout payload
D.Unsafe deserialization of untrusted JSON input
AnswerD

The payload's pathological depth targets the deserializer itself, driving recursive object graph construction until CPU and memory are consumed and the worker dies. Because the application binds arbitrary JSON straight into internal model objects with no depth or size limit, an attacker fully controls the structure parsed, which is exactly the unsafe deserialization condition that turns a normal data-parsing routine into a denial-of-service primitive.

Why this answer

The crash is caused by the deserializer recursively building an extremely deep object graph from attacker-supplied JSON, exhausting CPU and memory. When an API binds untrusted JSON directly to internal models without enforcing maximum depth, size, or allowed-property rules, the parsing stage itself becomes the attack surface. Incident handlers should correlate the crash with payload structure, then recommend depth limits, schema validation, and safe parser configuration.

Exam trap

The trap here is assuming any JSON-related outage must be mass assignment or injection, when the actual mechanism is resource exhaustion inside the deserializer.

Ready to test yourself?

Try a timed practice session using only Web App API Attacks questions.