
GIAC Certified Incident Handler
Domain 3Objective 1
Exploiting Insecure Web Application References GCIH Practice Questions (Page 4)
Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
6concepts
Questions 16–20
- 16
A security analyst is tasked with assessing a web application that uses sequential order numbers in the URL (e.g., /order?id=5000). The analyst wants to determine if the application is vulnerable to IDOR without causing disruption to legitimate users. Which approach is the most appropriate?
Select an answer first - 17
A development team is redesigning a document management system to prevent unauthorized access to files. Currently, users access files via /file?id=123. The team wants to eliminate predictable references while also ensuring that users cannot access files they do not own. Which design change best meets both goals?
Select an answer first - 18
An incident response team is investigating a breach where an attacker accessed the admin panel by manipulating the session cookie. The application stores the user's role in the cookie as a plaintext value. The team needs to remediate the vulnerability but also wants to maintain single sign-on (SSO) with an existing identity provider. Which approach is most appropriate?
Select an answer first - 19
An online banking application allows users to view their account statements via a URL like /statement?account=1001. A user changes the account parameter to 1002 and views another customer's statement. What is the root cause of this vulnerability?
Select an answer first - 20
A security analyst is testing a web application that uses sequential user IDs in the URL (e.g., /profile?id=100). The analyst wants to determine if the application is vulnerable to IDOR. Which of the following actions would best confirm the vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.