Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 3Objective 1

Exploiting Insecure Web Application References GCIH Practice Questions (Page 4)

Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
6concepts

Questions 16–20

  1. 16expert · hard

    A security analyst is tasked with assessing a web application that uses sequential order numbers in the URL (e.g., /order?id=5000). The analyst wants to determine if the application is vulnerable to IDOR without causing disruption to legitimate users. Which approach is the most appropriate?

    Select an answer first
  2. 17application · medium

    A development team is redesigning a document management system to prevent unauthorized access to files. Currently, users access files via /file?id=123. The team wants to eliminate predictable references while also ensuring that users cannot access files they do not own. Which design change best meets both goals?

    Select an answer first
  3. 18expert · medium

    An incident response team is investigating a breach where an attacker accessed the admin panel by manipulating the session cookie. The application stores the user's role in the cookie as a plaintext value. The team needs to remediate the vulnerability but also wants to maintain single sign-on (SSO) with an existing identity provider. Which approach is most appropriate?

    Select an answer first
  4. 19foundation · easy

    An online banking application allows users to view their account statements via a URL like /statement?account=1001. A user changes the account parameter to 1002 and views another customer's statement. What is the root cause of this vulnerability?

    Select an answer first
  5. 20application · medium

    A security analyst is testing a web application that uses sequential user IDs in the URL (e.g., /profile?id=100). The analyst wants to determine if the application is vulnerable to IDOR. Which of the following actions would best confirm the vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.