Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 3Objective 1

Exploiting Insecure Web Application References GCIH Practice Questions (Page 7)

Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
6concepts

Questions 31–35

  1. 31application · medium

    An incident responder notices that a web application's admin panel checks the HTTP header X-Admin: false to decide whether to show administrative functions. An attacker could simply change the header to X-Admin: true to gain admin access. Which of the following is the most appropriate remediation?

    Select an answer first
  2. 32application · medium

    A web application allows users to view reports by specifying a path parameter, such as /view?path=reports/2024/q1.pdf. An attacker discovers that using /view?path=../../../../etc/shadow returns the system shadow file. Which of the following is the most robust defense?

    Select an answer first
  3. 33application · medium

    During a penetration test, an analyst discovers that a web application uses sequential invoice numbers in the URL (e.g., /invoice?id=1001). The analyst writes a script to iterate through IDs and successfully retrieves invoices belonging to other customers. Which technique is the analyst primarily using?

    Select an answer first
  4. 34foundation · easy

    An attacker systematically tries different values for a user ID parameter in a web application to find records belonging to other users. Which exploitation technique is being used?

    Select an answer first
  5. 35expert · medium

    A web application serves static files from a directory that also contains sensitive configuration files. The application uses a path parameter to select files, and a recent penetration test found a path traversal vulnerability. The team wants to fix the vulnerability without moving the sensitive files to a different location. Which remediation is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.