CS0-003 Vulnerability Management Practice Question
A web application security tester uses Burp Suite to test an API endpoint. The tester sends a request with a modified HTTP method and discovers that the API accepts DELETE requests on an endpoint that should only allow GET. This is an example of which OWASP Top 10 vulnerability?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Broken Access Control
Improper handling of HTTP methods can lead to broken access control, allowing unauthorized actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Injection
Why it's wrong here
Injection vulnerabilities occur when untrusted user input is directly concatenated into an interpreter command or query, leading to unauthorized execution of code or database queries. While Burp Suite can test for this via SQLi or command injection payloads, the scenario specifically describes a failure in authorization boundaries rather than input parsing flaws.
- ✗
Security Misconfiguration
Why it's wrong here
Security misconfigurations involve default accounts, unhardened HTTP headers, or verbose error pages that leak system details. Although these weaknesses can expose an application to attack, they represent a failure in hardening and setup rather than a flaw in the application's logical enforcement of user privilege boundaries.
- ✗
Server-Side Request Forgery (SSRF)
Why it's wrong here
Server-Side Request Forgery occurs when a vulnerable web application is coerced into making unauthorized HTTP requests to backend systems or external APIs. This differs from access control failures, as SSRF exploits the server's trusted network position to bypass firewalls rather than manipulating user-level session permissions.
- ✓
Broken Access Control
Why this is correct
Broken access control is the correct answer because it directly describes a failure to enforce restrictions on what authenticated users are allowed to do. By manipulating parameters, headers, or API endpoints in Burp Suite, testers can identify flaws like Insecure Direct Object References (IDOR) or privilege escalation, which allow unauthorized data access.
Go deeper
Related to this question
Learn chapter
Executive Security Reporting
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Broken access control
Broken access control is a security vulnerability that occurs when an application does not properly enforce restrictions on what authenticated users are allowed to do, allowing them to access unauthorized data or perform unauthorized actions.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.