GCIH Web App API Attacks Practice Question
Which THREE items are essential components of an API security documentation strategy for incident responders?
⚠ Common exam trap
Candidates often select 'API keys' or 'authentication logs' as essential components. While useful, they are not structural documentation strategies required for incident responders to understand API behavior and baseline traffic patterns during an active event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Up-to-date OpenAPI/Swagger specifications
Effective incident response for APIs requires comprehensive documentation. API specifications (like OpenAPI/Swagger) provide the baseline for expected behavior and valid endpoints. Inventory documentation ensures all endpoints are known and monitored. Finally, security headers and rate-limiting policies document the defense-in-depth posture. Without these, responders cannot differentiate between legitimate traffic patterns and malicious exploitation attempts during an active security event or during post-incident forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Up-to-date OpenAPI/Swagger specifications
Why this is correct
OpenAPI documents provide a ground truth of the API's intended design, including expected input formats, authentication methods, and endpoint definitions. Responders use this to detect anomalies by comparing actual request structures against the documented schema to identify malicious variations or unexpected inputs.
- ✓
Complete inventory of all exposed API endpoints
Why this is correct
Shadow APIs and undocumented endpoints are prime targets for attackers. A complete inventory ensures that security teams can monitor and audit every entry point. Without knowing what is exposed, responders cannot effectively investigate unauthorized access or detect activity originating from forgotten or unmonitored legacy API endpoints.
- ✓
Detailed API rate-limiting and throttling policies
Why this is correct
Documented rate-limiting policies help distinguish between aggressive automated scanning and legitimate user traffic. Knowing the thresholds allows responders to determine if an attacker is attempting to bypass security or exhaust resources. This is crucial for configuring detection logic in WAFs or API gateways during incidents.
- ✗
Hardcoded database credentials for internal services
Why it's wrong here
Hardcoding credentials is a dangerous practice that violates fundamental security principles. Documentation should never contain sensitive secrets; instead, it should reference secure secret management systems like Vault. Including credentials in documentation introduces a high risk of compromise if the documentation itself is accessed by unauthorized actors.
- ✗
Customer personal identifiable information (PII) logs
Why it's wrong here
PII should not be stored in documentation or incident logs due to privacy regulations like GDPR. Including PII in documentation creates unnecessary liability and security risks. Incident response documentation should focus on metadata, behavioral patterns, and structural anomalies, never raw sensitive user data or customer information.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.