Courseiva
Web App API Attacks →hardMultiple Choice

GCIH Web App API Attacks Practice Question

During an incident involving a single-page application, a handler inspects a GraphQL endpoint at /graphql used for a customer portal. The handler captures a query that requests only the fields needed for a profile view, but the server response includes additional fields such as internalAccountTier, billingNotes, and ssnLastFour. The application uses a single shared GraphQL schema and no field-level authorization middleware. Which GraphQL-specific weakness is most directly demonstrated?

⚠ Common exam trap

The trap here is assuming that because the client requested only a few fields, the server cannot return more; in GraphQL, resolver output and schema design determine what is serialized, so over-fetching can expose sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Excessive data exposure from over-fetching sensitive fields in the GraphQL response

The response includes sensitive fields that the client did not request, and the server lacks field-level authorization to prevent their serialization. GraphQL resolvers return object properties according to schema and resolver logic, so sensitive data can leak even when the query appears minimal. The handler should focus on excessive data exposure and recommend field-level authorization, schema review, and response filtering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GraphQL aliasing used to perform a denial-of-service attack

    Why it's wrong here

    Aliasing allows a client to request the same field multiple times under different names, which can amplify resource usage. The scenario shows a normal profile query returning extra sensitive fields, not repeated aliases causing resource exhaustion. The handler would need to see many aliased fields or repeated expensive resolvers to justify an aliasing-based DoS finding.

  • ✓

    Excessive data exposure from over-fetching sensitive fields in the GraphQL response

    Why this is correct

    The endpoint returns sensitive fields that the client query did not request, and no field-level authorization prevents them from being serialized. In GraphQL, the server executes resolvers for fields selected by the query, but if a resolver or schema design includes sensitive properties in the returned object, the response can expose them. The handler should treat this as excessive data exposure and review resolver authorization and field visibility.

  • ✗

    GraphQL query batching used to bypass rate limits

    Why it's wrong here

    Query batching lets a client send multiple operations in one request, which can stress rate limiting or resource consumption controls. The captured query is a single profile request and the response includes unrequested sensitive fields. There is no evidence of multiple operations bundled together, so query batching is not the weakness demonstrated by the response contents.

  • ✗

    GraphQL introspection enabled on the production endpoint

    Why it's wrong here

    Introspection allows clients to query the schema for types, fields, and arguments. While introspection enabled in production is a hardening issue and aids reconnaissance, the scenario describes actual sensitive data appearing in a response to a normal profile query. The observed response contents point to excessive data exposure, not schema discovery, so introspection is not the most direct weakness shown here.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.