Certified Ethical Hacker (CEH) Practice Question

While testing a SaaS project-management API, you successfully retrieve your own project at /api/v1/projects/357 using a valid session cookie. To confirm whether horizontal authorization controls are missing, which modification to the captured request should you perform next?

  • Replace the project ID 357 with another sequential value such as 358 to see if data from a different account is returned.

  • Change the HTTP method from GET to OPTIONS to check for supported verbs.

  • Remove the Session cookie header entirely and resend the request to observe the server's default response.

  • Add the header X-Forwarded-For: 127.0.0.1 hoping the server will treat the request as internal.

Certified Ethical Hacker (CEH)
Web Application Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot