Courseiva

GCIH · domain

Web App Injection Attacks

This domain covers injection flaws in web applications: SQL injection via dynamic query construction, reflected and stored XSS, path traversal using encoded sequences, and command injection. GCIH questions present logs, exhibits, or code snippets and require identifying the vulnerability class, extracting attacker intent, and selecting effective defensive configurations.

28 questions2 easy16 medium10 hard

Focused practice

Practice Web App Injection Attacks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Web App Injection Attacks

Candidates must read logs, exhibits, or code to classify the injection type, then pick the correct defensive control. The single most important thing is distinguishing SQL injection, XSS, and path traversal by how input is used and reflected, not by payload appearance alone.

Identifying SQL injection when user input dynamically builds SQL statements and schema names are extracted

Recognizing reflected XSS where input lands in an HTML value attribute without output encoding

Detecting path traversal via q parameters containing ../../../etc/passwd or ....//....//etc/shadow

Choosing defenses like parameterized queries, HttpOnly cookies, input validation, and context-aware output encoding

Watch out for

Common Web App Injection Attacks exam traps

  • ▸Confusing reflected XSS with stored XSS when the exhibit only shows immediate reflection in a value attribute
  • ▸Assuming HttpOnly cookies stop XSS execution rather than only blocking JavaScript access to session cookies
  • ▸Missing path traversal when payloads use obfuscated sequences like ....// instead of plain ../

Question index

All Web App Injection Attacks questions (28)

Click any question to see the full explanation, or start a practice session above.

1

An incident handler is analyzing an incident where a web application was compromised via SQL injection. The backend database uses a modern relational database management system. Which TWO of the following remediation strategies are considered primary defenses against SQL injection attacks? (Choose TWO)

Hard
2

During an incident response engagement at a healthcare portal, an analyst reviews an Apache access.log entry: GET /report.php?view=..%2f..%2f..%2f..%2fetc%2fpasswd HTTP/1.1 with a 200 response size of 1845 bytes. The application runs as www-data on Linux and the 'view' parameter is passed directly to readfile() without sanitization. Which web application injection attack class best describes what the attacker successfully executed?

Hard
3

Refer to the exhibit. An application reflects user input directly into the HTML value attribute. What type of vulnerability is present?

Hard
4

During an incident response engagement, you discover that a web application constructs LDAP search filters by concatenating user input directly into the filter string. An attacker submits the username `*)(uid=*))(|(uid=*` into the login form and successfully authenticates as the first user in the directory. Which vulnerability class does this behavior represent?

Medium
5

A security analyst is reviewing an incident where an attacker submitted a specially crafted XML document to a SOAP API endpoint. The XML included a DOCTYPE declaration with an ENTITY that referenced file:///etc/passwd. The server's response contained the contents of that file. Which vulnerability was exploited?

Easy
6

An incident handler is examining a web application that stores user profiles in a MySQL database. A recent breach exposed data through a query that the application builds as: SELECT * FROM profiles WHERE username = '" + userInput + "'. The handler wants to recommend a code-level fix that eliminates this class of vulnerability. Which approach should be recommended?

Medium
7

An incident handler is reviewing WAF logs and notices repeated HTTP requests to a web application where the 'Host' header contains an attacker-controlled domain, while the request line targets the legitimate application server. The application uses the Host header to construct password-reset links emailed to users. Which web application injection attack class BEST describes this activity?

Medium
8

During incident response at a financial firm, an analyst discovers that a web application's login form is vulnerable to SQL injection. The backend is Microsoft SQL Server, and the application account has sysadmin rights. The attacker's payloads include ; EXEC xp_cmdshell 'whoami' -- and responses show the web server's service account name. Which immediate containment action best limits further damage while preserving evidence?

Hard
9

An incident handler is investigating a web application that uses a templating engine. The application allows users to submit their name, which is later rendered in a greeting page. An attacker submits the payload `{{7*7}}` and the page displays `49`. The application also exposes an endpoint that accepts a template name as a parameter. Which vulnerability is most likely present?

Hard
10

What is the primary difference between Stored XSS and Reflected XSS?

Medium
11

An incident investigator reviews application logs showing that an attacker manipulated session tokens by altering underlying JSON Web Tokens without knowing the signing secret. The attacker successfully forged valid-looking administrative sessions. Which server-side vulnerability enabled this behavior?

Medium
12

An incident handler is investigating a web application that uses a NoSQL database (MongoDB). The attacker sent a request with the parameter 'username[$ne]=admin&password[$ne]=wrong' and successfully authenticated as an administrator. Which of the following BEST describes the attack technique used?

Medium
13

During an incident response engagement involving a web application, an analyst uncovers evidence of Command Injection. Which TWO indicators or technical conditions strongly support this specific finding? (Choose TWO)

Medium
14

A security analyst notices that a web application reflects user-supplied input directly into an HTML attribute without encoding. An attacker crafts a URL that, when clicked by a victim, causes the victim's browser to execute a script that reads the victim's session cookie and sends it to an attacker-controlled server. Which type of attack is this?

Easy
15

An incident responder analyzes a web application log and discovers that an attacker successfully extracted database schema names by manipulating a parameter where the application dynamically constructs SQL statements. The database error messages returned verbose structural details. Which remediation strategy provides the most robust defense against this injection vector while maintaining application functionality?

Medium
16

An organization discovers that an attacker executed operating system commands via a vulnerable web application endpoint. The application takes user input, constructs an XML payload, and passes it to an underlying XML parser without disabling external entity resolution. Which type of vulnerability enabled this command execution?

Hard
17

Which TWO of the following techniques are most effective for preventing Cross-Site Scripting (XSS) in a web application?

Medium
18

An incident responder investigates a web application running a legacy PHP backend. Users report that searching for specific product SKUs causes the application to dump database table structures directly onto the results page. Which underlying vulnerability class is most likely responsible for this behavior?

Medium
19

An incident handler is analyzing a severe Cross-Site Scripting (XSS) incident where malicious JavaScript stole administrator session cookies. Which TWO of the following defensive configurations and practices effectively mitigate session theft risks via XSS?

Hard
20

A GCIH analyst is reviewing web server logs and sees repeated requests to /search?q=... where the q parameter contains strings like ../../../etc/passwd and ....//....//etc/shadow. The responses include root:x:0:0 entries. The application is a Java servlet that concatenates a user-supplied filename onto a base directory before calling new File(baseDir + userInput). Which vulnerability class best describes this incident?

Medium
21

Refer to the exhibit. If an attacker successfully injects <script>alert(1)</script> into a page, what happens?

Medium
22

An incident handler is analyzing a web application that uses a NoSQL database. The application constructs queries by directly embedding user input into JSON objects. An attacker submits a payload that includes `$ne` and `$gt` operators to bypass authentication. Which TWO of the following statements accurately describe this attack or its mitigation? (Choose two.)

Hard
23

A GCIH analyst is investigating a web application that uses Java deserialization to process user-supplied session objects. The analyst suspects an attacker exploited an insecure deserialization vulnerability to achieve remote code execution. Which two indicators are most likely to confirm this type of attack? (Choose two.)

Hard
24

When evaluating potential SQL injection in an application, what is the most significant indicator that an application is vulnerable?

Hard
25

An incident handler is investigating a web application that allows users to upload profile pictures. The application stores uploaded files in a directory accessible via the web and uses the original filename without sanitization. An attacker uploads a file named `shell.php.jpg` containing PHP code. The server executes the file when accessed via its URL. Which vulnerability has been exploited?

Medium
26

An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data by appending UNION SELECT statements to a numeric product ID parameter. Which backend remediation approach directly eliminates this vulnerability class while preserving application functionality?

Medium
27

Which of the following describes the primary danger of an Insecure Deserialization vulnerability in a web application?

Medium
28

During a web application penetration test, an assessor discovers an endpoint vulnerable to OS Command Injection via an improperly sanitized ping utility parameter. Which TWO remediation strategies provide robust defense against command injection vulnerabilities?

Medium

Frequently asked questions

What does the Web App Injection Attacks domain cover on the GCIH exam?
Candidates must read logs, exhibits, or code to classify the injection type, then pick the correct defensive control. The single most important thing is distinguishing SQL injection, XSS, and path traversal by how input is used and reflected, not by payload appearance alone.
How many questions are in this domain?
This page lists all 28 Web App Injection Attacks questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Web App Injection Attacks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcih GIAC-GCIH web app injection attacks Practice Questions