Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing a DAST scan report for a web application. The report indicates a vulnerability where the application fails to properly validate user-supplied data before using it in a database query. This is most likely which type of vulnerability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Injection

Failure to validate user input before using in a database query is classic SQL injection (injection flaw).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    While Cross-Site Scripting (XSS) is technically a sub-type of injection, it specifically targets the client-side browser by executing malicious scripts in the user's session. It does not involve sending malicious commands directly to a backend interpreter or database engine, which is the hallmark of classic injection vulnerabilities like SQLi or command injection.

  • ✗

    Security misconfiguration

    Why it's wrong here

    Security misconfigurations arise from improperly secured default settings, unpatched vulnerabilities, open directories, or verbose error messages rather than flawed input handling. While a DAST scanner will flag these infrastructure-level weaknesses, they are distinct from application-layer code flaws that fail to sanitize user-supplied input before processing.

  • ✓

    Injection

    Why this is correct

    Injection vulnerabilities occur when an application passes unfiltered, user-supplied input directly to an interpreter, such as a SQL database or system shell. This allows an attacker to manipulate the structure of the intended command, leading to unauthorized data access, modification, or arbitrary remote code execution on the host system.

  • ✗

    Broken access control

    Why it's wrong here

    Broken access control occurs when an application fails to properly enforce authorization boundaries, allowing users to access resources or perform actions outside their intended privileges. This is a logical flaw in privilege management, such as IDOR or directory traversal, rather than a failure to sanitize input passed to a backend interpreter.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.