ExamDumpster

Free GWEB sample questions

Real questions from the GIAC Web Application Defender practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 1 of 1 free sample questions.

Question 1Choose one

During a security assessment of a web application, you discover an API endpoint `GET /api/v1/users/{userId}/documents` that returns a list of documents for a given user. You observe that you can substitute your `userId` with that of another user and successfully retrieve their document list. The application correctly validates your authentication token for every request. What is the specific vulnerability category that best describes this issue? sequenceDiagram participant Attacker participant API_Gateway as API Gateway participant App_Server as Application Server participant DB as Database Attacker->>API_Gateway: GET /api/v1/users/VICTIM_ID/documents (with Attacker's valid token) API_Gateway->>App_Server: Forward Request (Auth check passes) App_Server->>DB: SELECT * FROM documents WHERE user_id = 'VICTIM_ID' Note right of App_Server: Fails to check if logged-in user matches VICTIM_ID DB-->>App_Server: Returns Victim's documents App_Server-->>API_Gateway: 200 OK with Victim's data API_Gateway-->>Attacker: Response with Victim's data

Ready for the full GWEB bank?

All 90 practice questions in study, timed and flashcard modes, with progress that saves.

Open the simulator