CS0-003 Vulnerability Management Practice Question
A security analyst is reviewing a DAST scan report for a web application. The report indicates a vulnerability where the application fails to properly validate user-supplied data before using it in a database query. This is most likely which type of vulnerability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Injection
Failure to validate user input before using in a database query is classic SQL injection (injection flaw).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
While Cross-Site Scripting (XSS) is technically a sub-type of injection, it specifically targets the client-side browser by executing malicious scripts in the user's session. It does not involve sending malicious commands directly to a backend interpreter or database engine, which is the hallmark of classic injection vulnerabilities like SQLi or command injection.
- ✗
Security misconfiguration
Why it's wrong here
Security misconfigurations arise from improperly secured default settings, unpatched vulnerabilities, open directories, or verbose error messages rather than flawed input handling. While a DAST scanner will flag these infrastructure-level weaknesses, they are distinct from application-layer code flaws that fail to sanitize user-supplied input before processing.
- ✓
Injection
Why this is correct
Injection vulnerabilities occur when an application passes unfiltered, user-supplied input directly to an interpreter, such as a SQL database or system shell. This allows an attacker to manipulate the structure of the intended command, leading to unauthorized data access, modification, or arbitrary remote code execution on the host system.
- ✗
Broken access control
Why it's wrong here
Broken access control occurs when an application fails to properly enforce authorization boundaries, allowing users to access resources or perform actions outside their intended privileges. This is a logical flaw in privilege management, such as IDOR or directory traversal, rather than a failure to sanitize input passed to a backend interpreter.
Go deeper
Related to this question
Learn chapter
Container Image Vulnerability Scanning
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.