CS0-003 Vulnerability Management Practice Question
During a web application security assessment using OWASP ZAP, a tester identifies that the application reflects user input in HTTP responses without proper encoding. Which OWASP Top 10 vulnerability category does this finding most likely belong to?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Injection
Reflected user input in responses without encoding is a classic sign of Cross-Site Scripting (XSS), which falls under injection in OWASP Top 10 (though XSS is specifically listed as a separate category in some versions, but in 2021 it is under injection).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Broken Access Control
Why it's wrong here
Broken access control relates to authorization flaws where users can act outside of their intended permissions, such as privilege escalation or unauthorized data access. While OWASP ZAP can detect these vulnerabilities through active scanning of access paths, the specific scenario of executing untrusted scripts in a user's browser is classified under injection rather than authorization bypass.
- ✗
Cryptographic Failures
Why it's wrong here
Cryptographic failures involve flaws in encryption, such as using weak algorithms, transmitting sensitive data in cleartext, or failing to enforce TLS. Although OWASP ZAP identifies weak cipher suites and missing secure flags on cookies, these issues represent data protection failures rather than the active payload execution characteristic of cross-site scripting.
- ✗
Security Misconfiguration
Why it's wrong here
Security misconfiguration involves insecure settings, such as leaving default accounts active, enabling unnecessary features, or displaying verbose error messages. While a missing Content Security Policy header is a misconfiguration that exacerbates XSS, the root cause of XSS itself is the failure to sanitize input, which falls squarely under the injection category.
- ✓
Injection
Why this is correct
Injection occurs when untrusted user input is directly interpreted as code by an interpreter. Cross-Site Scripting (XSS) is a specific type of injection vulnerability where malicious scripts are injected into benign and trusted websites. During an OWASP ZAP assessment, the tool identifies this by injecting payload strings and verifying if they execute within the context of the victim's browser session.
Go deeper
Related to this question
Learn chapter
User and Entity Behaviour Analytics (UEBA)
Key term
Security assessment
A security assessment is a systematic evaluation of an organization’s systems, networks, and applications to identify vulnerabilities, threats, and risks, and to recommend improvements.
Key term
Cross-site scripting
Cross-site scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users, often to steal data or hijack sessions.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.