Courseiva
mediumMultiple Choice

CS0-003 Practice Question: A SOC analyst is reviewing logs from a web server…

A SOC analyst is reviewing logs from a web server and sees the following request: GET /../../etc/passwd HTTP/1.1. Which type of web attack is this?

⚠ Common exam trap

CompTIA often tests the distinction between directory traversal and file inclusion; the trap here is confusing the '../' path manipulation with SQL injection or XSS because the request looks like a simple GET, but the attack vector is purely about file system access, not database or script injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Directory traversal

The request GET /../../etc/passwd HTTP/1.1 uses '../' sequences to traverse directories outside the web root, attempting to read the /etc/passwd file. This is the classic signature of a directory traversal (path traversal) attack, which exploits insufficient input validation to access unauthorized files on the server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    This attack vector is incorrect because the log entries lack database query syntax, such as UNION SELECT, OR 1=1, or single quotes used to escape input fields. SQL injection targets the database layer behind the web application rather than attempting to access the local file system directly through the web server's directory structure.

  • ✗

    Cross-site request forgery (CSRF)

    Why it's wrong here

    CSRF involves tricking an authenticated user's browser into executing an unwanted action on a trusted site. The log entries do not show state-changing requests initiated via third-party referrers or missing anti-CSRF tokens, which would characterize a forged request exploit attempt.

  • ✓

    Directory traversal

    Why this is correct

    The log entries clearly display dot-dot-slash (../) sequences, or their URL-encoded equivalents like %2e%2e%2f, which are classic signatures of a directory traversal attack. This exploit attempts to escape the web root directory to access restricted system files, such as /etc/passwd or boot configuration files.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    XSS attacks require the injection of malicious client-side scripts, typically utilizing HTML tags like <script> or event handlers like onload to execute code in a victim's browser. Because the web server logs do not contain any script payloads, HTML markup, or JavaScript syntax, this classification is incorrect.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.