Courseiva

GCIH · topic practice

Web App API Attacks practice questions

This GCIH domain covers attacks against web applications and APIs, including REST parameter tampering, IDOR, GraphQL abuse, and injection flaws. Questions test whether you can identify the failed security control, map the attack to the OWASP-style category, and choose the correct incident response action or documentation artifact.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Web App API Attacks

What the exam tests

What to know about Web App API Attacks

Be able to read an API request, spot the modified identifier or query, and name the exact failed control (object-level authorization, not authentication). For GraphQL, identify missing depth or complexity limits as the cause of denial of service.

Identifying broken object level authorization (IDOR) when integer identifiers in REST paths or query parameters are modified

Recognizing GraphQL resource exhaustion from deeply nested or overly complex queries leading to denial of service

Selecting essential API security documentation components for incident responders, such as authentication schemes and endpoint inventories

Distinguishing authentication failures from authorization failures when a low-privileged user reaches administrative records

Watch out for

Common Web App API Attacks exam traps

  • ▸Labeling IDOR as broken authentication; the user is authenticated, so the failure is authorization or access control at the object level.
  • ▸Assuming input validation fixes IDOR; the fix is server-side authorization checks per object, not sanitizing the identifier.
  • ▸Treating GraphQL depth attacks as injection; they are resource exhaustion or lack of query cost limiting, not code injection.

Practice set

Web App API Attacks questions

20 questions · select your answer, then reveal the explanation

Refer to the exhibit. Which security vulnerability is most directly represented by the presence of the 'debug_info' field in the API response?

Exhibit

HTTP/1.1 200 OK
Content-Type: application/json

{
  "status": "success",
  "data": {
    "user": "admin",
    "role": "superuser",
    "debug_info": "SELECT * FROM users WHERE id=101"
  }
}

A GCIH incident handler is called to investigate a web application that uses a REST API. The handler observes that the API accepts a 'callback' parameter and reflects its value directly in the JSON response without any sanitization. Which type of attack is most directly enabled by this behavior?

An incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?

During a web application incident investigation, the SOC analyst discovers that an attacker sent a modified JSON payload containing an unexpected administrative attribute "is_admin": true during user registration, which successfully elevated the user's privileges. What vulnerability enabled this exploitation?

An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /api/v1/user/details?id=124. This vulnerability indicates a failure in which security control?

Which TWO methods are effective for mitigating Mass Assignment vulnerabilities in RESTful APIs?

An API uses OAuth 2.0. An attacker sends a request with a modified 'redirect_uri' parameter to an authorization endpoint. If successful, this could lead to which type of vulnerability?

Which THREE items are essential components of an API security documentation strategy for incident responders?

When analyzing a JSON Web Token (JWT) for potential security weaknesses in an API, which scenario indicates a 'None' algorithm attack is possible?

Which security measure is most effective against API-based Denial of Service (DoS) attacks targeted at resource-intensive endpoints?

Refer to the exhibit. An attacker changes the 'final_price' to 0.00. What is the most likely vulnerability?

Exhibit

POST /api/v1/payment HTTP/1.1
Host: api.example.com
Content-Type: application/json

{
  "item_id": 500,
  "price": 100.00,
  "discount": 0.00,
  "final_price": 100.00
}

Which of the following is the most significant security risk associated with the use of 'API Keys' for authentication in modern cloud-native environments?

In the context of API security, what does the 'Broken Object Level Authorization' (BOLA) vulnerability typically involve?

Which THREE actions are recommended to secure APIs against Server-Side Request Forgery (SSRF)?

An incident responder is analyzing an API access log and notices a user with ID 104 is able to modify account settings for user ID 105 by simply changing the integer value in the URI endpoint from /api/v1/users/104/settings to /api/v1/users/105/settings without any additional token validation or role checks. Which specific OWASP API Security Top 10 vulnerability class does this scenario represent?

An incident responder is investigating a modern web application and notices that users can modify object identifiers in REST API endpoints to access sensitive records belonging to other tenants. Which primary vulnerability category does this represent?

An incident responder is investigating a RESTful API breach where an authenticated low-privileged user accessed administrative records by modifying an integer identifier in the resource path from /api/v1/users/104 to /api/v1/users/1. Which type of vulnerability has been exploited?

During a penetration test of a GraphQL API, an incident handler finds that the introspection system is enabled and can be queried without authentication. The handler retrieves the full schema, including hidden fields and mutations. What is the most significant security impact of this finding?

An incident responder is analyzing a web application that uses a REST API. The API accepts a 'file' parameter that specifies a URL from which to fetch an image. The responder observes that an attacker supplied a URL pointing to an internal metadata service (e.g., http://169.254.169.254/latest/meta-data/) and successfully retrieved sensitive instance credentials. Which vulnerability class does this represent?

A GCIH incident handler is reviewing web server logs after a suspected API reconnaissance campaign. The logs show numerous requests to endpoints such as /api/v1/users, /api/v2/users, /api/v3/users, and /api/internal/users, all returning HTTP 404 except one. Which attack technique is most consistent with this pattern?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Web App API Attacks sessions

Start a Web App API Attacks only practice session

Every question in these sessions is drawn from the Web App API Attacks domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Web App API Attacks?
Be able to read an API request, spot the modified identifier or query, and name the exact failed control (object-level authorization, not authentication). For GraphQL, identify missing depth or complexity limits as the cause of denial of service.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Web App API Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Web App API Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.