Courseiva

GCIH Exploiting Insecure Web App References Practice Question

During a web application penetration test, you notice that a request to `/download?doc=8841` returns a PDF belonging to a different department. You change the value to `8842` and receive another department's document. The session cookie remains unchanged for both requests. Which conclusion best fits these observations?

⚠ Common exam trap

The trap here is concluding that sequential identifiers are the root cause, when the fundamental defect is the absence of a server-side ownership check on the requested object.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The endpoint lacks object-level authorization, allowing any authenticated user to retrieve documents by changing the direct reference.

Changing a numeric parameter returned a document belonging to another department under the same authenticated session. That demonstrates the server resolves the requested object and returns it without verifying the caller's entitlement. The remedy is object-level authorization: resolve the document, confirm the session principal may access it, and deny the request when that relationship is absent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The endpoint lacks object-level authorization, allowing any authenticated user to retrieve documents by changing the direct reference.

    Why this is correct

    The same session retrieved two different departments' documents simply by incrementing a numeric parameter. That is the classic signature of an insecure direct object reference: the server accepts the client-supplied identifier and returns the object without verifying entitlement. The unchanged session cookie confirms the requests came from one identity, ruling out session confusion as the explanation.

  • ✗

    The numeric document identifiers are sequential and therefore guessable, which is the root cause of the cross-department access.

    Why it's wrong here

    Sequential identifiers make enumeration trivial, but they are not the root cause. If the server verified ownership, guessing another department's document number would return an authorization error rather than the file. Replacing the numbers with random values would slow an attacker but leave the missing check in place, so the underlying flaw would persist.

  • ✗

    The session cookie is not bound to the document owner, so the application must regenerate it on every download to prevent cross-department access.

    Why it's wrong here

    Session cookies identify the user, not the document. Regenerating the cookie per download would not add an ownership check; the same user would still receive both documents. The problem is that the server never compares the requested document to the user's entitlements. Cookie regeneration addresses session fixation, not object authorization, so it would not remediate this behavior.

  • ✗

    The download endpoint is missing a CSRF token, allowing an attacker to force the victim's browser to fetch arbitrary documents.

    Why it's wrong here

    CSRF protection prevents an attacker's site from causing a victim's browser to issue authenticated requests. Here the tester directly changed the parameter and received the file, which is an authorization failure rather than a request-forgery issue. Adding CSRF tokens would not stop an authenticated user from requesting document 8842, so it does not explain or fix the observed behavior.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.