Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

An analyst is reviewing a Nessus scan report and sees a plugin result that indicates a web application is vulnerable to SQL injection. The plugin output includes the payload used and the database error message. Which OWASP Top 10 category does this vulnerability belong to?

⚠ Common exam trap

The trap is misclassifying SQL injection under Broken Access Control or Authentication Failures — candidates see 'database' or 'login' and pick the wrong category, but SQLi is definitively A03:2021 – Injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A03:2021 – Injection

SQL injection is a classic injection flaw where untrusted input is interpreted as code by the database. In the OWASP Top 10 2021, SQL injection falls under A03:2021 – Injection, which encompasses SQL, NoSQL, OS command, ORM, and LDAP injection. The plugin output showing a payload and database error confirms injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A03:2021 – Injection

    Why this is correct

    SQL injection lets an attacker insert untrusted input into a database query so it is executed as code rather than data, which is the exact definition of the OWASP Injection category and explains the payload and error message in the output.

  • ✗

    A07:2021 – Identification and Authentication Failures

    Why it's wrong here

    Authentication failures cover credential stuffing, weak passwords and session management, not database query manipulation. It is tempting because injection attacks often begin at login forms, but the payload and database error here point to A03:2021 – Injection.

  • ✗

    A09:2021 – Security Logging and Monitoring Failures

    Why it's wrong here

    Security Logging and Monitoring Failures describe an absence of detection capability, such as missing audit trails that let attacks go unnoticed; the SQLi finding is a direct exploitable flaw, unrelated to whether it was logged.

  • ✗

    A01:2021 – Broken Access Control

    Why it's wrong here

    Broken Access Control covers missing authorisation checks and privilege escalation, not injection of SQL syntax into queries. It is tempting because both are web application flaws, but the payload and database error message here indicate A03:2021 – Injection.

Go deeper

Related to this question

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.