Courseiva

GCIH · topic practice

Exploiting Insecure Web App References practice questions

This domain covers insecure direct object references (IDOR), path traversal, and local file inclusion in web applications. For GCIH, questions present scenarios like Base64-encoded object IDs, predictable numeric parameters, or PHP filter wrappers, requiring you to identify the missing authorization check and explain why encoding or obscurity fails as a security control.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Exploiting Insecure Web App References

What the exam tests

What to know about Exploiting Insecure Web App References

A candidate must be able to identify missing server-side authorization checks in object references and file inclusion parameters. The single most important thing is to verify access control using two distinct user accounts, because encoding, predictable IDs, or client-side controls do not prevent unauthorized access.

Identifying IDOR when changing a numeric user_id parameter returns another user's profile

Recognizing Base64-encoded object references as reversible and not an authorization control

Testing with two distinct user accounts to confirm horizontal privilege escalation

Analyzing LFI via php://filter/convert.base64-encode/resource= in web server logs

Watch out for

Common Exploiting Insecure Web App References exam traps

  • ▸Assuming Base64 encoding provides security; it is reversible and does not enforce authorization.
  • ▸Testing IDOR with only one account, missing unauthorized access that a second account would reveal.
  • ▸Confusing path traversal with LFI; LFI includes local files via wrappers, while traversal moves directories.

Practice set

Exploiting Insecure Web App References questions

20 questions · select your answer, then reveal the explanation

Which of the following is a primary indicator that an application is vulnerable to Insecure Direct Object Reference (IDOR)?

Which THREE of the following are common consequences of a successful Path Traversal attack?

Which TWO of the following steps are critical for a secure implementation of file downloads in a web application?

An attacker uses a non-sequential, randomly generated ID to access resources, but is still successful in an IDOR attack. What does this suggest about the application's design?

Why does using an allow-list for file extensions fail to stop Path Traversal attacks?

You are responding to an incident involving a Java web application that streams reports to users. The endpoint accepts a `report` parameter and passes it to `new File(baseDir, report)` before reading the file. Logs show a request containing `%252e%252e%252f` in the parameter, and the response contained the contents of a configuration file outside the base directory. The application's input filter rejects the literal string `../` but nothing else. Which weakness in the filter most directly explains the successful escape?

A web application uses a JSON Web Token (JWT) for session management. The token is signed with the HS256 algorithm. A security tester captures a token and notices that the payload contains a `role` claim set to `user`. The tester attempts to modify the `role` to `admin` but the signature verification fails. The tester then changes the algorithm header to `none` and removes the signature. The modified token is accepted by the server, granting administrative access. Which vulnerability has been exploited?

An attacker manipulates a URL parameter `?file=invoice_123.pdf` to `?file=../../etc/passwd` on a web server. The application successfully returns the sensitive system file content. Which vulnerability is being exploited?

Which TWO of the following practices are the most effective at mitigating Insecure Direct Object Reference (IDOR) vulnerabilities?

When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two distinct user accounts?

An application uses a Base64 encoded string as a parameter for object references. An attacker decodes the string, modifies the ID, re-encodes it, and successfully accesses unauthorized data. Why did the security control fail?

Which of the following is the most secure method for handling file references in a web application to prevent path traversal?

Which of the following is the most critical step to perform after detecting a successful IDOR exploit?

How can an application distinguish between an authorized user requesting their own profile and an unauthorized user attempting to access a different profile via IDOR?

Which of the following describes the core difference between Path Traversal and IDOR?

An incident handler investigates a web application breach where an authenticated user modified a hidden form parameter containing an integer account ID, successfully viewing financial records belonging to other customers. Which underlying vulnerability class allowed this unauthorized data access?

A penetration tester discovers that a web application uses a predictable numeric parameter `user_id` in the URL to retrieve user profiles. While authenticated as user 1001, the tester changes the parameter to 1002 and successfully views another user's profile. The application does not perform any additional authorization checks beyond verifying the session. Which of the following best describes the vulnerability and its immediate impact?

A security analyst is reviewing a web application that uses a parameter `doc_id` to retrieve documents from a database. The application does not validate that the requested document belongs to the authenticated user. During an incident response, the analyst observes multiple requests with sequential `doc_id` values from a single IP address. Which TWO of the following actions should the analyst take to confirm and mitigate the IDOR vulnerability? (Choose two.)

A web application allows users to download files by specifying a filename in the URL, such as `download?file=report.pdf`. An attacker changes the parameter to `download?file=../../../../etc/passwd` and successfully retrieves the system's password file. Which of the following best describes this attack?

A security engineer is reviewing a web application that uses a parameter `account` to retrieve account details. The parameter value is a base64-encoded string of the account number, such as `YWNjb3VudD0xMjM0`. An attacker decodes the string, changes the account number, re-encodes it, and successfully accesses another user's account. Which of the following is the most likely reason this attack succeeded?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Exploiting Insecure Web App References sessions

Start a Exploiting Insecure Web App References only practice session

Every question in these sessions is drawn from the Exploiting Insecure Web App References domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Exploiting Insecure Web App References?
A candidate must be able to identify missing server-side authorization checks in object references and file inclusion parameters. The single most important thing is to verify access control using two distinct user accounts, because encoding, predictable IDs, or client-side controls do not prevent unauthorized access.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Exploiting Insecure Web App References questions in a focused session?
Yes — the session launcher on this page draws every question from the Exploiting Insecure Web App References domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.