Courseiva
mediumMultiple Choice

CCSP Practice Question: An API endpoint returns user profile data…

An API endpoint returns user profile data including fields like 'credit_card_number' even when the client application does not need it. Which OWASP API security risk does this represent?

⚠ Common exam trap

ISC2 often tests the distinction between Excessive Data Exposure and Mass Assignment, where candidates mistakenly choose Mass Assignment because both involve 'extra data,' but Mass Assignment specifically applies to write operations (e.g., PUT/POST) where an attacker modifies fields they shouldn't, not to read responses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Excessive Data Exposure

The API returns sensitive data (credit_card_number) that the client application does not need, violating the principle of least data exposure. This is a classic Excessive Data Exposure risk (OWASP API Security Top 10 #3), where the server trusts the client to filter the response rather than limiting the fields returned based on the client's actual authorization or need.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Injection

    Why it's wrong here

    Injection concerns untrusted data altering query or command structure, such as SQL or LDAP payloads reaching an interpreter. Here no input is being manipulated; the endpoint simply over-returns stored fields. Injection would be the answer if user-supplied input were concatenated into a database query without parameterisation.

  • ✗

    Broken Object Level Authorization

    Why it's wrong here

    Broken Object Level Authorization concerns accessing other users' objects by manipulating identifiers, not excessive data in a legitimate response. It tempts because both are API authorisation issues, but returning unneeded fields such as credit_card_number is Excessive Data Exposure.

  • ✗

    Mass Assignment

    Why it's wrong here

    Mass Assignment occurs when client-supplied input binds to internal object properties the client should not set, letting attackers modify fields. This scenario is the reverse direction: the server exposes excess fields in its response. Mass Assignment would fit if a client could POST a role or balance field and have it persisted.

  • ✓

    Excessive Data Exposure

    Why this is correct

    Excessive Data Exposure occurs when an API returns full object properties and relies on the client to filter fields, so sensitive attributes like credit_card_number reach clients that never needed them. This matches the stem exactly, unlike Broken Object Property Level Authorisation.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.