Courseiva
Web App API Attacks →mediumMultiple Choice

GCIH Web App API Attacks Practice Question

During a web application incident investigation, the SOC analyst discovers that an attacker sent a modified JSON payload containing an unexpected administrative attribute "is_admin": true during user registration, which successfully elevated the user's privileges. What vulnerability enabled this exploitation?

⚠ Common exam trap

Candidates often misidentify this as 'Broken Object Level Authorization' (BOLA). While related to privilege, 'Mass Assignment' specifically refers to the binding of unexpected user input to internal object attributes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mass Assignment

Mass assignment occurs when frameworks automatically bind user input parameters directly to backend data models without proper filtering. This allows attackers to inject privileged fields that were never intended to be exposed during client-side registration forms. GCIH handlers must trace data binding configurations and ensure explicit allowlisting of updatable attributes to prevent privilege escalation incidents via API request tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Broken User Authentication

    Why it's wrong here

    Broken authentication weaknesses involve flaws in credential management, session handling, or password recovery mechanisms that allow attackers to compromise user accounts. Injecting hidden parameters into a valid registration request is an input binding issue rather than an authentication credential bypass vulnerability.

  • ✗

    Server-Side Request Forgery

    Why it's wrong here

    Server-Side Request Forgery allows an attacker to manipulate the application server into issuing unintended network requests to internal or external systems. Modifying object properties within a JSON payload sent directly to an API endpoint is completely unrelated to outbound server-side HTTP networking.

  • ✓

    Mass Assignment

    Why this is correct

    Mass assignment arises when automated object mapping features bind HTTP request parameters directly to internal data structure properties. Attackers exploit this by appending sensitive fields like role or status flags to registration or profile update payloads to gain unauthorized administrative privileges.

  • ✗

    Cross-Site Scripting

    Why it's wrong here

    Cross-Site Scripting allows malicious scripts to execute within a victim's browser context due to improper output encoding or input sanitization. Injecting JSON attributes to manipulate server-side data models represents an API data binding flaw rather than client-side script injection.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.