GCIH Exploiting Insecure Web App References Practice Question
Which of the following is the most critical step to perform after detecting a successful IDOR exploit?
⚠ Common exam trap
Students mistakenly prioritize shutting down the entire web server or rotating all administrator passwords immediately, rather than first determining the specific breach scope via logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit access logs to assess the scope of data exposure
The most critical step is to perform a comprehensive audit to determine the scope of unauthorized access. Since IDOR exploits are often automated, an attacker could have scraped the entire database. Identifying which user records were exposed is essential for compliance, incident reporting, and notifying affected parties. Without a thorough impact assessment, you cannot quantify the damage or ensure the vulnerability has not been used to exfiltrate bulk sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restart the web server service
Why it's wrong here
Restarting the web server does not remediate an IDOR vulnerability, which is a software logic flaw. It only clears current memory state or session data temporarily. The vulnerability will persist until the application code is updated to verify authorization for all object access requests at the application level, not the server level.
- ✓
Audit access logs to assess the scope of data exposure
Why this is correct
IDOR vulnerabilities frequently allow mass data exfiltration. After detection, the priority is identifying how much data was accessed by the attacker. Analyzing access logs helps quantify the breach, allowing for an accurate impact assessment and compliance reporting, which are required when handling incidents that expose personal or sensitive organizational data.
- ✗
Block the attacker's IP address on the firewall
Why it's wrong here
While blocking an IP address is a standard short-term containment measure, it is ineffective against distributed attacks or attackers using proxies and VPNs. It does not address the root cause of the vulnerability. The application remains insecure and vulnerable to other attackers who can easily bypass a simple IP-based filter.
- ✗
Rotate all user passwords in the system
Why it's wrong here
Password rotation is only necessary if credentials were specifically compromised. IDOR vulnerabilities expose data without necessarily compromising passwords. Unless there is evidence that the attacker accessed sensitive password files or account credentials, rotating passwords does not address the underlying authorization logic flaw that enabled the unauthorized object access in the first place.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.