PCI Approved Scanning Vendor (ASV) Online Practice Test

Access More Questions
Insecure direct object references and directory traversal are examples of which vulnerability category?
Correct Answer:
Improper access control
Explanation:
These examples show a failure to enforce proper authorization for accessing resources. Insecure direct object references occur when an app exposes direct references to internal objects (like IDs) and doesn’t verify that the requester is allowed to access that object; changing the reference can reveal or modify data the user shouldn’t see. Directory traversal likewise lets an attacker manipulate file paths to reach restricted files outside the intended directory, bypassing access checks. Both highlight weaknesses in controlling who can access what, which is the essence of improper access control. The other options describe different issues: cross-site scripting involves injecting scripts into pages, CSRF tricks a user into performing unintended actions, and broken authentication concerns weaknesses in login or session management.

Access more questions from this quiz

Continue to PCI Approved Scanning Vendor (ASV) Online Practice Test for more practice questions and the full quiz experience.

Access More Questions