Courseiva

GCIH Exploiting Insecure Web App References Practice Question

When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two distinct user accounts?

⚠ Common exam trap

Candidates frequently assume testing requires guessing complex passwords or bypassing authentication mechanisms entirely, missing the specific utility of multi-account cross-referencing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To confirm that the application does not validate object ownership

Testing with two accounts allows the auditor to verify if User A can access User B's resources using the same identifiers. This 'cross-account' test is the gold standard for confirming an IDOR vulnerability. It isolates the logic flaw by demonstrating that the application fails to validate ownership, proving that access control is tied only to authentication rather than granular authorization, which is a critical finding for secure development.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To verify if the server is load balanced

    Why it's wrong here

    Testing with multiple accounts is intended to probe authorization logic, not to test infrastructure performance or load balancing. Load balancing concerns are separate from the security of resource access control, and using multiple users would not provide meaningful data about the underlying server distribution architecture.

  • ✗

    To ensure that session cookies are not reused

    Why it's wrong here

    Session management security ensures that tokens are unique, secure, and expire correctly. Using two accounts helps identify authorization flaws, not session management issues. While testing for session reuse is important, it is distinct from identifying IDOR vulnerabilities where the primary focus is object-level access control.

  • ✓

    To confirm that the application does not validate object ownership

    Why this is correct

    By logging in as User A and attempting to access an object owned by User B, the auditor confirms if the application performs authorization checks. If the request succeeds, it proves the system only validates the session, not the ownership of the referenced object, confirming the IDOR flaw.

  • ✗

    To test the strength of the password hashing

    Why it's wrong here

    Password hashing strength is tested by analyzing the algorithm and salt implementation, not by accessing objects in the application. Using two user accounts in an IDOR test provides no information about how the system stores credentials, as the focus is on the application's resource access logic.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.