Courseiva
Web App API Attacks →mediumMultiple Choice

GCIH Web App API Attacks Practice Question

During a penetration test of a GraphQL API, an incident handler finds that the introspection system is enabled and can be queried without authentication. The handler retrieves the full schema, including hidden fields and mutations. What is the most significant security impact of this finding?

⚠ Common exam trap

The trap here is assuming introspection directly leads to code execution or authentication bypass, when it primarily enables reconnaissance and targeted attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attackers can map the entire API surface, identify sensitive fields and mutations, and craft targeted queries to abuse them.

Exposed GraphQL introspection lets attackers retrieve the full schema, including hidden fields and mutations. This information disclosure enables them to craft precise queries and mutations that target sensitive operations, significantly lowering the effort required for further exploitation. The other options either misstate the technical effect or focus on less likely outcomes. Therefore, schema mapping and targeted abuse is the most significant impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attackers can directly execute arbitrary code on the GraphQL server through introspection queries.

    Why it's wrong here

    Introspection only returns metadata about the schema; it does not execute code or allow arbitrary command execution. While exposed introspection aids reconnaissance, it does not by itself grant code execution. The attacker would need a separate vulnerability, such as a deserialization flaw or a vulnerable resolver, to achieve that. Therefore, this option overstates the impact and is not the most significant consequence of the finding.

  • ✗

    Attackers can bypass authentication by sending a specially crafted introspection query that returns valid session tokens.

    Why it's wrong here

    Introspection queries do not return session tokens or authentication credentials; they only describe the schema. Authentication bypass requires a flaw in the authentication mechanism itself, such as weak token validation or misconfigured middleware. Introspection does not interact with the authentication layer in that way. Thus, this option misrepresents the purpose and output of introspection.

  • ✗

    Attackers can cause a denial of service by sending an introspection query that recursively expands the schema indefinitely.

    Why it's wrong here

    While introspection can be resource-intensive, it does not recursively expand indefinitely by design; the schema is finite. A denial of service via introspection is possible but requires overwhelming the server with complex queries, not a single recursive query. The most direct impact of exposed introspection is information disclosure, not DoS. This option mischaracterizes the primary risk.

  • ✓

    Attackers can map the entire API surface, identify sensitive fields and mutations, and craft targeted queries to abuse them.

    Why this is correct

    Introspection reveals types, fields, arguments, and mutations, giving attackers a complete blueprint of the API. This enables precise targeting of sensitive operations, such as user data retrieval or privilege escalation via mutations. The exposure significantly reduces the effort needed for further attacks, making it a serious information disclosure issue. This is the primary risk when introspection is left enabled without authentication.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.