Courseiva
Web App API Attacks →hardMultiple Choice

GCIH Web App API Attacks Practice Question

During an incident response engagement, a GCIH analyst examines an API that accepts JSON input and notices that the application returns detailed database error messages when a single quote is inserted into the 'username' field. The analyst also observes that the same endpoint returns a 500 error when a specially crafted JSON object with nested arrays is submitted. Which vulnerability class is the analyst most likely investigating?

⚠ Common exam trap

The trap here is focusing on the 500 error as a simple crash rather than recognizing it as a symptom of improper input validation that often accompanies injection vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Injection flaws, such as SQL injection and improper input validation

The combination of database error messages in response to a single quote and a 500 error from malformed nested JSON indicates that the application is not properly validating or sanitizing input before passing it to backend interpreters. This is a classic sign of injection flaws, which can lead to data compromise or remote code execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Insecure direct object references (IDOR)

    Why it's wrong here

    IDOR involves accessing objects by manipulating identifiers, typically leading to unauthorized data access. The scenario does not mention object identifiers or access to other users' records; it focuses on input-triggered errors. Therefore, IDOR is not the primary vulnerability being investigated.

  • ✗

    Excessive data exposure in API responses

    Why it's wrong here

    Excessive data exposure occurs when APIs return more data than necessary, such as full objects instead of filtered fields. Here, the issue is error messages and input handling, not the volume of data returned. The errors themselves may leak information, but the root cause is injection and validation, not data exposure.

  • ✓

    Injection flaws, such as SQL injection and improper input validation

    Why this is correct

    Detailed database errors on quote injection strongly suggest SQL injection, while the 500 error on malformed nested JSON indicates insufficient input validation. Together, they point to injection flaws where untrusted input reaches interpreters or parsers. This is consistent with the analyst's observations and is a high-severity finding.

  • ✗

    Broken authentication via weak API keys

    Why it's wrong here

    Weak API keys would manifest as unauthorized access or token reuse, not as database errors triggered by input manipulation. The scenario describes error responses to crafted input, which is characteristic of injection, not authentication bypass. No authentication artifacts are mentioned.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.