CS0-003 Vulnerability Management Practice Question
A security analyst is investigating a reported vulnerability in a web application. The team uses Burp Suite for DAST scanning. Which TWO of the following findings would be classified as injection vulnerabilities according to OWASP Top 10?
⚠ Common exam trap
Test-takers frequently confuse other OWASP Top 10 categories (like broken access control or vulnerable components) with injection, because candidates may not recall that XSS is classified under injection in the 2021 list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stored XSS in the comment section
Option C (Stored XSS in the comment section) is correct because cross-site scripting is classified under OWASP Top 10 A03:2021 Injection, where untrusted user input is interpreted as code (HTML/JavaScript) by the browser, and the stored variant persists the payload in the application's database. Option E (SQL injection in the login form) is correct because SQLi is the canonical injection flaw, where attacker-supplied input alters the structure of a SQL query executed by the backend database, also falling under A03:2021 Injection. Option A does not belong because using a component with known vulnerabilities maps to A06:2021 Vulnerable and Outdated Components, not injection. Option B does not belong because broken access control is its own category, A01:2021, involving authorization failures rather than input being interpreted as code or commands. Option D does not belong because security misconfiguration maps to A05:2021 and concerns improper hardening (such as exposed directory listings), not injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use of a component with known vulnerabilities
Why it's wrong here
This issue falls under 'Vulnerable and Outdated Components' (A06:2021), not an injection attack. Using a library or module with known Common Vulnerabilities and Exposures (CVEs) means the application inherits those flaws, but an attacker must still trigger the vulnerable code path. Unlike XSS or SQLi, this isn't about sending crafted payloads into user-supplied input; it's a supply-chain hygiene failure that leads to exposure of a pre-existing bug.
- ✗
Broken access control allowing privilege escalation
Why it's wrong here
Broken access control (A01:2021) is a separate authorization flaw where an application fails to enforce proper restrictions on what authenticated users can do. This often manifests as horizontal or vertical privilege escalation, such as tampering with a URL parameter or role ID to gain admin rights. It is not an injection vulnerability, because no malicious input is assembled into a script or query; the attack simply exploits missing server-side policy checks.
- ✓
Stored XSS in the comment section
Why this is correct
Stored XSS in the comment section is an injection vulnerability because the attacker injects executable client-side script (e.g., JavaScript) that is persisted on the server and later rendered in other users' browsers. Unlike SQL injection, which targets the database layer with structured query language, XSS targets the interpretation context of HTML/JavaScript in the victim's browser. The comment field fails to sanitize or encode user input, enabling script execution that can steal session cookies, deface pages, or perform actions on behalf of the target user.
- ✗
Security misconfiguration exposing directory listing
Why it's wrong here
Security misconfiguration (A05:2021) is an infrastructure or application configuration error, such as enabling directory listing on a web server, leaving default credentials, or verbose error messages. This exposes sensitive files or metadata to anyone who requests the directory, but it does not involve injecting code or queries. It is a static condition that reflects omitted hardening, not an active attack technique; the information disclosure it causes can aid further attacks but is not itself an injection flaw.
- ✓
SQL injection in the login form
Why this is correct
SQL injection in the login form is a direct injection vulnerability because attacker-supplied data is concatenated into a SQL query without parameterized statements. By inserting malicious SQL payloads (e.g., ' OR 1=1 --), an attacker can bypass authentication, alter records, or dump the database. This is distinct from XSS, which targets the browser with scripts; SQLi targets the backend database engine and manipulates query logic, often with catastrophic confidentiality and integrity impact.
Go deeper
Related to this question
Learn chapter
Risk Scoring and Heat Maps
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
OWASP Top 10
The OWASP Top 10 is a regularly updated list of the most critical security risks to web applications, published by the Open Web Application Security Project (OWASP) to help developers and security professionals prioritize and mitigate common vulnerabilities.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.