GCIH Web App API Attacks Practice Question
During a web application incident investigation, the SOC analyst discovers that an attacker sent a modified JSON payload containing an unexpected administrative attribute "is_admin": true during user registration, which successfully elevated the user's privileges. What vulnerability enabled this exploitation?
⚠ Common exam trap
Candidates often misidentify this as 'Broken Object Level Authorization' (BOLA). While related to privilege, 'Mass Assignment' specifically refers to the binding of unexpected user input to internal object attributes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mass Assignment
Mass assignment occurs when frameworks automatically bind user input parameters directly to backend data models without proper filtering. This allows attackers to inject privileged fields that were never intended to be exposed during client-side registration forms. GCIH handlers must trace data binding configurations and ensure explicit allowlisting of updatable attributes to prevent privilege escalation incidents via API request tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Broken User Authentication
Why it's wrong here
Broken authentication weaknesses involve flaws in credential management, session handling, or password recovery mechanisms that allow attackers to compromise user accounts. Injecting hidden parameters into a valid registration request is an input binding issue rather than an authentication credential bypass vulnerability.
- ✗
Server-Side Request Forgery
Why it's wrong here
Server-Side Request Forgery allows an attacker to manipulate the application server into issuing unintended network requests to internal or external systems. Modifying object properties within a JSON payload sent directly to an API endpoint is completely unrelated to outbound server-side HTTP networking.
- ✓
Mass Assignment
Why this is correct
Mass assignment arises when automated object mapping features bind HTTP request parameters directly to internal data structure properties. Attackers exploit this by appending sensitive fields like role or status flags to registration or profile update payloads to gain unauthorized administrative privileges.
- ✗
Cross-Site Scripting
Why it's wrong here
Cross-Site Scripting allows malicious scripts to execute within a victim's browser context due to improper output encoding or input sanitization. Injecting JSON attributes to manipulate server-side data models represents an API data binding flaw rather than client-side script injection.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.