Courseiva

GCIH · topic practice

Web App Injection Attacks practice questions

This domain covers injection flaws in web applications: SQL injection via dynamic query construction, reflected and stored XSS, path traversal using encoded sequences, and command injection. GCIH questions present logs, exhibits, or code snippets and require identifying the vulnerability class, extracting attacker intent, and selecting effective defensive configurations.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Web App Injection Attacks

What the exam tests

What to know about Web App Injection Attacks

Candidates must read logs, exhibits, or code to classify the injection type, then pick the correct defensive control. The single most important thing is distinguishing SQL injection, XSS, and path traversal by how input is used and reflected, not by payload appearance alone.

Identifying SQL injection when user input dynamically builds SQL statements and schema names are extracted

Recognizing reflected XSS where input lands in an HTML value attribute without output encoding

Detecting path traversal via q parameters containing ../../../etc/passwd or ....//....//etc/shadow

Choosing defenses like parameterized queries, HttpOnly cookies, input validation, and context-aware output encoding

Watch out for

Common Web App Injection Attacks exam traps

  • ▸Confusing reflected XSS with stored XSS when the exhibit only shows immediate reflection in a value attribute
  • ▸Assuming HttpOnly cookies stop XSS execution rather than only blocking JavaScript access to session cookies
  • ▸Missing path traversal when payloads use obfuscated sequences like ....// instead of plain ../

Practice set

Web App Injection Attacks questions

20 questions · select your answer, then reveal the explanation

An application uses a parameterized query: SELECT * FROM users WHERE username = ?. If an attacker inputs 'OR 1=1' into the username field, what is the most likely outcome?

Which THREE of the following are recommended practices for mitigating Command Injection vulnerabilities?

An incident responder investigates a web application running a legacy PHP backend. Users report that searching for specific product SKUs causes the application to dump database table structures directly onto the results page. Which underlying vulnerability class is most likely responsible for this behavior?

An incident handler is analyzing an incident where a web application was compromised via SQL injection. The backend database uses a modern relational database management system. Which TWO of the following remediation strategies are considered primary defenses against SQL injection attacks? (Choose TWO)

An organization discovers that an attacker executed operating system commands via a vulnerable web application endpoint. The application takes user input, constructs an XML payload, and passes it to an underlying XML parser without disabling external entity resolution. Which type of vulnerability enabled this command execution?

During an incident response engagement involving a web application, an analyst uncovers evidence of Command Injection. Which TWO indicators or technical conditions strongly support this specific finding? (Choose TWO)

An incident investigator reviews application logs showing that an attacker manipulated session tokens by altering underlying JSON Web Tokens without knowing the signing secret. The attacker successfully forged valid-looking administrative sessions. Which server-side vulnerability enabled this behavior?

Which TWO of the following techniques are most effective for preventing Cross-Site Scripting (XSS) in a web application?

Refer to the exhibit. An application reflects user input directly into the HTML value attribute. What type of vulnerability is present?

Exhibit

HTTP/1.1 200 OK
Content-Type: text/html

<html>
  <form action="/search" method="GET">
    <input type="text" name="q" value="' OR 1=1 --">
  </form>
</html>

Which of the following describes the primary danger of an Insecure Deserialization vulnerability in a web application?

What is the primary difference between Stored XSS and Reflected XSS?

Refer to the exhibit. If an attacker successfully injects <script>alert(1)</script> into a page, what happens?

Exhibit

Content-Security-Policy: default-src 'self'; script-src 'self' https://trusted.cdn.com;

When evaluating potential SQL injection in an application, what is the most significant indicator that an application is vulnerable?

An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data by appending UNION SELECT statements to a numeric product ID parameter. Which backend remediation approach directly eliminates this vulnerability class while preserving application functionality?

An incident handler is analyzing a severe Cross-Site Scripting (XSS) incident where malicious JavaScript stole administrator session cookies. Which TWO of the following defensive configurations and practices effectively mitigate session theft risks via XSS?

During a web application penetration test, an assessor discovers an endpoint vulnerable to OS Command Injection via an improperly sanitized ping utility parameter. Which TWO remediation strategies provide robust defense against command injection vulnerabilities?

An incident responder analyzes a web application log and discovers that an attacker successfully extracted database schema names by manipulating a parameter where the application dynamically constructs SQL statements. The database error messages returned verbose structural details. Which remediation strategy provides the most robust defense against this injection vector while maintaining application functionality?

An incident handler is reviewing WAF logs and notices repeated HTTP requests to a web application where the 'Host' header contains an attacker-controlled domain, while the request line targets the legitimate application server. The application uses the Host header to construct password-reset links emailed to users. Which web application injection attack class BEST describes this activity?

An incident handler is investigating a web application that uses a NoSQL database (MongoDB). The attacker sent a request with the parameter 'username[$ne]=admin&password[$ne]=wrong' and successfully authenticated as an administrator. Which of the following BEST describes the attack technique used?

A GCIH analyst is reviewing web server logs and sees repeated requests to /search?q=... where the q parameter contains strings like ../../../etc/passwd and ....//....//etc/shadow. The responses include root:x:0:0 entries. The application is a Java servlet that concatenates a user-supplied filename onto a base directory before calling new File(baseDir + userInput). Which vulnerability class best describes this incident?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Web App Injection Attacks sessions

Start a Web App Injection Attacks only practice session

Every question in these sessions is drawn from the Web App Injection Attacks domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Web App Injection Attacks?
Candidates must read logs, exhibits, or code to classify the injection type, then pick the correct defensive control. The single most important thing is distinguishing SQL injection, XSS, and path traversal by how input is used and reflected, not by payload appearance alone.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Web App Injection Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Web App Injection Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.