
GIAC Certified Incident Handler
Domain 3Objective 1
Exploiting Insecure Web Application References GCIH Practice Questions (Page 5)
Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
6concepts
Questions 21–25
- 21
A penetration tester is assessing a web application that uses numeric IDs for invoices. The tester wants to determine if the application is vulnerable to IDOR by accessing invoices belonging to other users. Which testing approach is most effective?
Select an answer first - 22
A development team is building a new document management system. They want to prevent both IDOR and path traversal attacks. Which design choice is most effective?
Select an answer first - 23
A web application allows users to transfer money using a form with a hidden field 'recipient_account'. An attacker changes this field to another user's account number and submits the form. What is the primary vulnerability?
Select an answer first - 24
A security analyst is reviewing logs and notices that a user is accessing the admin panel by adding the parameter ?admin=true to the URL. The application checks this parameter to enable admin features. Which of the following is the best immediate action to stop this access control bypass?
Select an answer first - 25
A web application has multiple vulnerabilities, including IDOR and path traversal. The development team wants to implement a comprehensive fix that addresses both issues with minimal changes to the user interface. Which approach is the most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.