GCIH Web App API Attacks Practice Question
Which security measure is most effective against API-based Denial of Service (DoS) attacks targeted at resource-intensive endpoints?
⚠ Common exam trap
Candidates frequently choose 'Web Application Firewalls' (WAF). While WAFs assist, rate limiting is the specific, most effective architectural control for preventing resource exhaustion at the API endpoint level itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing robust rate limiting
Rate limiting is the standard defense against resource exhaustion in APIs. By enforcing limits on the number of requests a client can make within a specific timeframe, the API prevents a single user or bot from monopolizing backend CPU, memory, or database connections. This ensures that the service remains available to other legitimate users, mitigating the risk of intentional or accidental system degradation caused by heavy API consumption patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforcing HTTPS for all traffic
Why it's wrong here
HTTPS provides confidentiality and integrity for data in transit. While essential, it does not prevent a client from sending many legitimate but resource-intensive requests that consume backend server resources, leading to a Denial of Service. HTTPS protects the transport, not the server's resource availability.
- ✓
Implementing robust rate limiting
Why this is correct
Rate limiting restricts the frequency of requests from a specific source, preventing attackers from overloading the API with resource-intensive requests. This ensures that system resources are distributed fairly and prevents any single source from exhausting the server's capacity, which is the primary goal of API DoS prevention.
- ✗
Using JWTs for authentication
Why it's wrong here
JWTs are an authentication mechanism. While they verify the identity of the requester, they do not restrict how often an authenticated user can hit an endpoint. An authenticated attacker can still trigger a DoS by repeatedly calling an expensive function, so JWTs do not prevent DoS.
- ✗
Disabling CORS headers
Why it's wrong here
CORS controls browser-side access to APIs across domains. It is not an anti-DoS mechanism. An attacker using a command-line tool like curl or a custom script will ignore CORS headers entirely, rendering this control ineffective against API-based DoS attacks originating from non-browser environments.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.