GCIH Web App API Attacks Practice Question
Which of the following is the most significant security risk associated with the use of 'API Keys' for authentication in modern cloud-native environments?
⚠ Common exam trap
Candidates often focus on 'lack of encryption' or 'weak hashing'. These are secondary concerns; the primary systemic risk of API keys is their static, long-lived nature that makes them permanent secrets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They are static secrets prone to leakage
API keys are often static and long-lived, making them highly susceptible to theft through code repository leaks, log exposure, or interception. Once stolen, they are difficult to rotate and often grant broad access. Unlike short-lived tokens like OAuth access tokens, static keys lack expiration, context, and granular scope, creating a significant security burden for organizations that fail to implement strict rotation and revocation procedures for their distributed keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They are easily cracked using brute-force tools
Why it's wrong here
API keys are typically high-entropy random strings, making them resistant to brute-force attacks. The primary risk is not that they can be guessed, but that they can be stolen or leaked from insecure storage locations, leading to unauthorized persistent access to the API services.
- ✗
They cannot be used over HTTPS connections
Why it's wrong here
API keys are frequently sent over HTTPS, which protects them from network sniffing. The limitation is not the protocol, but the fact that they are static secrets. If the key is leaked, the channel encryption doesn't help because the attacker possesses the valid secret key itself.
- ✓
They are static secrets prone to leakage
Why this is correct
API keys are long-lived static secrets that often appear in source code, configuration files, or logs. Since they typically grant permanent access until revoked, their leakage represents a high risk, as attackers can use the stolen keys indefinitely without needing to re-authenticate or renew session tokens.
- ✗
They are incompatible with RESTful architecture
Why it's wrong here
API keys are perfectly compatible with RESTful services and are widely used for simple authentication. While less secure than OAuth for complex requirements, their use does not violate the REST paradigm. The issue with keys is the security risk of long-lived secrets, not architectural compatibility.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.