
GIAC Certified Incident Handler
Domain 3Objective 1
Exploiting Insecure Web Application References GCIH Practice Questions (Page 9)
Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
6concepts
Questions 41–43
- 41
An attacker notices that document IDs in a web application are sequential integers (e.g., 1001, 1002, 1003). The attacker guesses the next ID and accesses a document they should not see. Which exploitation technique is this?
Select an answer first - 42
A multi-tenant SaaS application allows tenants to manage their own data. Each tenant has a unique tenant ID, and data is accessed via /api/data?tenantId=abc123. A security audit reveals that changing the tenantId to another tenant's ID returns that tenant's data. The application uses API keys for authentication, but the API key is not tied to a specific tenant. The company must fix this without requiring tenants to change their API keys. Which solution is most appropriate?
Select an answer first - 43
A healthcare portal allows patients to view their lab reports by clicking a link that includes a numeric report ID in the URL. During a review, a security analyst notices that changing the ID to an adjacent number displays another patient's report. The application does not verify that the logged-in user owns the report. Which remediation best addresses the root cause?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.