Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

During a web application security assessment using OWASP ZAP, a tester identifies that the application reflects user input in HTTP responses without proper encoding. Which OWASP Top 10 vulnerability category does this finding most likely belong to?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Injection

Reflected user input in responses without encoding is a classic sign of Cross-Site Scripting (XSS), which falls under injection in OWASP Top 10 (though XSS is specifically listed as a separate category in some versions, but in 2021 it is under injection).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Broken Access Control

    Why it's wrong here

    Broken access control relates to authorization flaws where users can act outside of their intended permissions, such as privilege escalation or unauthorized data access. While OWASP ZAP can detect these vulnerabilities through active scanning of access paths, the specific scenario of executing untrusted scripts in a user's browser is classified under injection rather than authorization bypass.

  • ✗

    Cryptographic Failures

    Why it's wrong here

    Cryptographic failures involve flaws in encryption, such as using weak algorithms, transmitting sensitive data in cleartext, or failing to enforce TLS. Although OWASP ZAP identifies weak cipher suites and missing secure flags on cookies, these issues represent data protection failures rather than the active payload execution characteristic of cross-site scripting.

  • ✗

    Security Misconfiguration

    Why it's wrong here

    Security misconfiguration involves insecure settings, such as leaving default accounts active, enabling unnecessary features, or displaying verbose error messages. While a missing Content Security Policy header is a misconfiguration that exacerbates XSS, the root cause of XSS itself is the failure to sanitize input, which falls squarely under the injection category.

  • ✓

    Injection

    Why this is correct

    Injection occurs when untrusted user input is directly interpreted as code by an interpreter. Cross-Site Scripting (XSS) is a specific type of injection vulnerability where malicious scripts are injected into benign and trusted websites. During an OWASP ZAP assessment, the tool identifies this by injecting payload strings and verifying if they execute within the context of the victim's browser session.

Go deeper

Related to this question

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.