hardMultiple Select
CCSP Practice Question: A cloud application exposes an API that allows…
A cloud application exposes an API that allows users to view their own orders. Which TWO vulnerabilities could allow an attacker to view another user's orders?
⚠ Common exam trap
CCSP often tests the distinction between authentication and authorization, and candidates may confuse IDOR/BOLA with other injection or data exposure flaws; the trap is selecting SQL Injection or Excessive Data Exposure when the core issue is missing object-level access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insecure Direct Object Reference (IDOR)
Insecure Direct Object Reference (IDOR) (C) is correct because the API likely uses a user-controllable identifier such as an order ID or user ID in the request, and if the application fails to verify that the referenced object belongs to the authenticated user, an attacker can simply change that identifier to access another user's orders. Broken Object Level Authorization (BOLA) (D) is correct because it is the API-specific authorization flaw where the server does not properly enforce object-level access checks on each request, allowing an authenticated user to read objects belonging to other users even when the endpoint itself is properly authenticated. Excessive Data Exposure (A) is not correct here because it concerns returning more data fields than necessary in a response, not accessing another user's records. SQL Injection (B) is not correct because it involves manipulating backend SQL queries through unsanitized input, which is a different attack class than directly referencing another user's object. Cross-Site Scripting (E) is not correct because XSS executes script in a victim's browser and does not by itself grant access to another user's orders.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Excessive Data Exposure
Why it's wrong here
Excessive Data Exposure returns more fields than the UI needs within records the caller is already entitled to; it does not let a user request another user's order. It is tempting because it leaks sensitive attributes, and it would be correct if the API returned full order objects containing other customers' data in a shared response.
- ✗
SQL Injection
Why it's wrong here
SQL injection manipulates database queries through unsanitised input, but viewing another user's orders requires the query to lack an ownership filter tied to the authenticated identity. It is tempting because it breaches data stores, yet it would be correct when attacker input alters query structure to expose arbitrary records.
- ✓
Insecure Direct Object Reference (IDOR)
Why this is correct
IDOR occurs when the API trusts a user-supplied object identifier, such as an order ID, without verifying ownership. An attacker simply increments or guesses another user's identifier and the endpoint returns that order, exposing data across tenants.
- ✓
Broken Object Level Authorization (BOLA)
Why this is correct
BOLA is the API-specific failure where the endpoint authenticates the caller but never checks whether that caller is authorised for the requested object. Changing the order identifier therefore returns another user's order, because authorisation is enforced at function level only.
- ✗
Cross-Site Scripting (XSS)
Why it's wrong here
XSS injects scripts into pages, not directly related to viewing other orders.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.