Courseiva
Web App API Attacks →hardMultiple Choice

GCIH Web App API Attacks Practice Question

Which THREE actions are recommended to secure APIs against Server-Side Request Forgery (SSRF)?

⚠ Common exam trap

Candidates often select client-side validation techniques or general firewall rules, forgetting that SSRF requires server-side restrictions like URL allow-lists and network segmentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a strict allow-list for URLs

SSRF occurs when an API is tricked into making requests to internal or unauthorized external resources. To prevent this, developers must use strict allow-lists for destination domains, disable unused URL schemes (like file://), and enforce network-level segmentation that restricts the API server's ability to reach internal management interfaces or metadata services. These layers of defense ensure that even if an input parameter is compromised, the server remains isolated from critical internal assets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a strict allow-list for URLs

    Why this is correct

    Allow-lists ensure the API server only makes requests to trusted, predefined domains. By rejecting requests to unexpected or internal endpoints, the risk of the server being used as a proxy to attack internal infrastructure is significantly reduced, effectively mitigating the primary target of most SSRF exploits.

  • ✓

    Disable unused URI schemes like file:// or gopher://

    Why this is correct

    Many SSRF attacks leverage non-HTTP schemes to read local files or interact with internal services. Restricting the API to only allow 'http' and 'https' schemes prevents the use of these alternative protocols for data exfiltration or internal system interaction, narrowing the available attack surface for SSRF.

  • ✓

    Network-level segmentation of the API server

    Why this is correct

    Segmenting the API server into a restrictive network zone prevents it from reaching sensitive internal management interfaces, metadata services, or databases. If the server is compromised via SSRF, the network segmentation limits the attacker's ability to pivot deeper into the internal network, protecting critical infrastructure assets.

  • ✗

    Use a public proxy for all outgoing requests

    Why it's wrong here

    Using a public proxy does not fix SSRF. If the proxy itself is not configured to filter requests, the attacker can still use it to perform malicious actions. Furthermore, it adds unnecessary complexity and potentially exposes traffic to the proxy provider without providing any actual security benefits.

  • ✗

    Store all API secrets in the URL parameters

    Why it's wrong here

    Storing secrets in URL parameters is an extremely insecure practice that facilitates credential leakage through logs, browser history, and proxy servers. This practice is entirely unrelated to SSRF mitigation and actually introduces significant new security risks related to information disclosure and credential theft.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.