Courseiva

GCIH Exploiting Insecure Web App References Practice Question

Which TWO of the following practices are the most effective at mitigating Insecure Direct Object Reference (IDOR) vulnerabilities?

⚠ Common exam trap

Candidates often select 'hiding' techniques like encoding IDs as a primary mitigation. They fail to realize that only server-side authorization checks provide true protection against unauthorized object access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing server-side authorization checks for every object access

Mitigating IDOR requires shifting from user-controlled identifiers to server-side access control checks. Relying on unpredictable identifiers makes guessing harder, but verifying identity and authorization for every requested object is the primary defense. These practices ensure that even if an attacker discovers a valid ID, they lack the authorization to perform operations on the underlying data, thereby closing the logical gap that allows unauthorized object access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implementing server-side authorization checks for every object access

    Why this is correct

    Verifying that the current authenticated user has explicit permission to access the requested object is the definitive mitigation for IDOR. Without this server-side validation, users can simply modify request parameters to view data belonging to other users, rendering any other security control ineffective against logical authorization bypasses.

  • ✓

    Using random, non-sequential identifiers for objects

    Why this is correct

    Transitioning from sequential integers to globally unique identifiers (UUIDs) makes it computationally infeasible for attackers to enumerate or guess valid object references. While this does not replace authorization, it significantly reduces the attack surface by preventing trivial discovery of resources through automated scanning or manual parameter incrementing.

  • ✗

    Increasing the length of session tokens

    Why it's wrong here

    Session token length primarily impacts protection against session hijacking and brute-force attacks on credentials. It does not address the logic flaw inherent in IDOR, where the session is valid, but the user is accessing an object they are not authorized to view or modify through parameter tampering.

  • ✗

    Employing a Web Application Firewall (WAF)

    Why it's wrong here

    While WAFs can detect common attack patterns, they struggle to identify logical IDOR vulnerabilities because they lack context regarding user ownership of specific data objects. An attacker modifying an ID from 101 to 102 appears as a valid request, making WAF filtering insufficient for this specific threat.

  • ✗

    Moving all sensitive data to a cloud storage bucket

    Why it's wrong here

    Relocating data does not address the underlying IDOR vulnerability, which is rooted in the application's access logic. Unless the cloud bucket permissions are explicitly configured to enforce object-level ownership checks per user, the application will remain susceptible to unauthorized access through insecure direct object references.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.