Skip to content

GWEB Practice Questions

Prepare for GWEB with more than an answer.

90 questions in the full set1 sample questionsUpdated Oct 18, 2025
Exam fee
$999 USD
Level
Practitioner
Valid for
4 years
Domains covered on the exam 8
  1. Web Fundamentals and Architecture15%
  2. Input Validation and Injection Attacks20%
  3. Authentication and Session Management18%
  4. Access Control and Authorization12%
  5. Cross-Origin and CSRF Attacks10%
  6. Data Protection and Cryptography8%
  7. Web Services and API Security10%
  8. Modern Web Technologies7%
  1. 1

    During a security assessment of a web application, you discover an API endpoint GET /api/v1/users/{userId}/documents that returns a list of documents for a given user. You observe that you can substitute your userId with that of another user and successfully retrieve their document list. The application correctly validates your authentication token for every request. What is the specific vulnerability category that best describes this issue?

    sequenceDiagram participant Attacker participant API_Gateway as API Gateway participant App_Server as Application Server participant DB as Database Attacker->>API_Gateway: GET /api/v1/users/VICTIM_ID/documents (with Attacker's valid token) API_Gateway->>App_Server: Forward Request (Auth check passes) App_Server->>DB: SELECT * FROM documents WHERE user_id = 'VICTIM_ID' Note right of App_Server: Fails to check if logged-in user matches VICTIM_ID DB-->>App_Server: Returns Victim's documents App_Server-->>API_Gateway: 200 OK with Victim's data API_Gateway-->>Attacker: Response with Victim's data

    Show answer details

    Correct answer: B

    This scenario perfectly describes an Insecure Direct Object Reference (IDOR) vulnerability, which is a type of broken access control. The application authenticates the user correctly but fails to authorize them for the specific resource they are requesting. It uses a direct reference to an object (the userId) from user-supplied input without verifying that the authenticated user has permission to access that specific object.

Create an account to continue.