Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 3Objective 2

Web Application API Attacks GCIH Practice Questions (Page 6)

Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
7concepts

Questions 26–30

  1. 26application · medium

    An API has been compromised through a vulnerability that allows attackers to reset other users' passwords. The incident response team has identified the affected endpoint and the vulnerability. Which of the following is the most important immediate step to prevent further exploitation?

    Select an answer first
  2. 27expert · hard

    A social media API is experiencing an attack where attackers use a botnet to create fake accounts and post spam. The API has rate limiting per IP, but the botnet uses thousands of different IPs. The company wants to reduce spam without blocking legitimate users who may share IPs (e.g., corporate NAT). Which approach is the most effective?

    Select an answer first
  3. 28application · medium

    A healthcare API accepts a patient ID as a query parameter to retrieve records. A security analyst notices that when the parameter is changed to a value like '1 OR 1=1', the API returns all patient records. The API uses parameterized queries for other inputs. Which action would best mitigate this vulnerability?

    Select an answer first
  4. 29foundation · easy

    An API endpoint returns the full database record for a user, including internal notes and password hashes, when a client requests a user profile. Which type of vulnerability is this?

    Select an answer first
  5. 30expert · hard

    A company is migrating its internal APIs to a public cloud. The APIs handle sensitive customer data and must comply with data residency regulations that require data to remain in a specific country. The security team wants to ensure that only authorized internal applications can access the APIs. Which approach best meets both requirements?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.