
GIAC Certified Incident Handler
Domain 3Objective 2
Web Application API Attacks GCIH Practice Questions (Page 10)
Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 46–49
- 46
A healthcare API returns patient records. The API uses OAuth 2.0 with scopes to control access. A developer notices that the 'patient:read' scope returns the full medical history, including mental health notes, but the mobile app only needs basic demographics. The API is also returning verbose error messages that reveal database schema details. Which two issues are present?
Select an answer first - 47
A security analyst is reviewing API logs and identifies the following indicators: a high number of requests to /api/v1/search with a 'q' parameter containing SQL-like syntax, a spike in 500 errors, and requests originating from a single IP address at a rate of 100 requests per second. Which of the following attacks are likely occurring? Select all that apply.
Select an answer first - 48
A financial app's API endpoint /account/{id} returns the full account object, including internal fields like 'internal_notes' and 'routing_number', to any authenticated user who knows the account ID. The API does not check whether the user owns the account. What is the primary vulnerability?
Select an answer first - 49
During an API incident, which of the following is the FIRST step in the incident response process?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.