Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

A web application security tester uses Burp Suite to test an API endpoint. The tester sends a request with a modified HTTP method and discovers that the API accepts DELETE requests on an endpoint that should only allow GET. This is an example of which OWASP Top 10 vulnerability?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Broken Access Control

Improper handling of HTTP methods can lead to broken access control, allowing unauthorized actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Injection

    Why it's wrong here

    Injection vulnerabilities occur when untrusted user input is directly concatenated into an interpreter command or query, leading to unauthorized execution of code or database queries. While Burp Suite can test for this via SQLi or command injection payloads, the scenario specifically describes a failure in authorization boundaries rather than input parsing flaws.

  • ✗

    Security Misconfiguration

    Why it's wrong here

    Security misconfigurations involve default accounts, unhardened HTTP headers, or verbose error pages that leak system details. Although these weaknesses can expose an application to attack, they represent a failure in hardening and setup rather than a flaw in the application's logical enforcement of user privilege boundaries.

  • ✗

    Server-Side Request Forgery (SSRF)

    Why it's wrong here

    Server-Side Request Forgery occurs when a vulnerable web application is coerced into making unauthorized HTTP requests to backend systems or external APIs. This differs from access control failures, as SSRF exploits the server's trusted network position to bypass firewalls rather than manipulating user-level session permissions.

  • ✓

    Broken Access Control

    Why this is correct

    Broken access control is the correct answer because it directly describes a failure to enforce restrictions on what authenticated users are allowed to do. By manipulating parameters, headers, or API endpoints in Burp Suite, testers can identify flaws like Insecure Direct Object References (IDOR) or privilege escalation, which allow unauthorized data access.

Go deeper

Related to this question

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.