GCIH Exploiting Insecure Web App References Practice Question
Which TWO of the following practices are the most effective at mitigating Insecure Direct Object Reference (IDOR) vulnerabilities?
⚠ Common exam trap
Candidates often select 'hiding' techniques like encoding IDs as a primary mitigation. They fail to realize that only server-side authorization checks provide true protection against unauthorized object access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing server-side authorization checks for every object access
Mitigating IDOR requires shifting from user-controlled identifiers to server-side access control checks. Relying on unpredictable identifiers makes guessing harder, but verifying identity and authorization for every requested object is the primary defense. These practices ensure that even if an attacker discovers a valid ID, they lack the authorization to perform operations on the underlying data, thereby closing the logical gap that allows unauthorized object access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing server-side authorization checks for every object access
Why this is correct
Verifying that the current authenticated user has explicit permission to access the requested object is the definitive mitigation for IDOR. Without this server-side validation, users can simply modify request parameters to view data belonging to other users, rendering any other security control ineffective against logical authorization bypasses.
- ✓
Using random, non-sequential identifiers for objects
Why this is correct
Transitioning from sequential integers to globally unique identifiers (UUIDs) makes it computationally infeasible for attackers to enumerate or guess valid object references. While this does not replace authorization, it significantly reduces the attack surface by preventing trivial discovery of resources through automated scanning or manual parameter incrementing.
- ✗
Increasing the length of session tokens
Why it's wrong here
Session token length primarily impacts protection against session hijacking and brute-force attacks on credentials. It does not address the logic flaw inherent in IDOR, where the session is valid, but the user is accessing an object they are not authorized to view or modify through parameter tampering.
- ✗
Employing a Web Application Firewall (WAF)
Why it's wrong here
While WAFs can detect common attack patterns, they struggle to identify logical IDOR vulnerabilities because they lack context regarding user ownership of specific data objects. An attacker modifying an ID from 101 to 102 appears as a valid request, making WAF filtering insufficient for this specific threat.
- ✗
Moving all sensitive data to a cloud storage bucket
Why it's wrong here
Relocating data does not address the underlying IDOR vulnerability, which is rooted in the application's access logic. Unless the cloud bucket permissions are explicitly configured to enforce object-level ownership checks per user, the application will remain susceptible to unauthorized access through insecure direct object references.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.