Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester discovers a Java application…

A penetration tester discovers a Java application that deserializes user-controlled data without validation. The tester crafts a malicious serialized object that executes a command upon deserialization. The application runs on a Linux server with a standard Java runtime. Which of the following is the most likely outcome if the malicious object is accepted?

⚠ Common exam trap

The trap here is that candidates often conflate 'arbitrary command execution' with 'gaining a shell' (Option C), but the exam expects the broader, more precise impact—arbitrary command execution—since a shell is just one specific form of command execution and not guaranteed by every payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The tester will be able to execute arbitrary commands on the server.

Java deserialization of untrusted data allows an attacker to supply a crafted serialized object that, when deserialized, can execute arbitrary code via gadget chains (e.g., CommonsCollections). Since the application runs on a Linux server with a standard Java runtime, the attacker can achieve remote code execution (RCE) with the privileges of the application's user, not necessarily an interactive shell. Option D is correct because the primary impact is arbitrary command execution, which may or may not yield a shell depending on the payload.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application will crash immediately due to an exception.

    Why it's wrong here

    A crash is not the defining outcome of Java deserialization abuse. While a malformed or incompatible payload can throw exceptions such as InvalidClassException or ClassNotFoundException, a crafted gadget chain leverages readObject() to execute code without triggering a fatal error; the payload is designed to complete cleanly so the application keeps running after code execution.

  • ✗

    The application will disclose sensitive information in the response.

    Why it's wrong here

    Insecure deserialization does not directly cause sensitive information to appear in the HTTP response; it leads to arbitrary code execution via gadget chains that invoke methods like Runtime.exec(). Any information disclosure would be a secondary result of running commands to read files or access data, not the automatic output of the deserialization flaw itself.

  • ✗

    The tester will gain a shell with the privileges of the current user.

    Why it's wrong here

    Gaining a shell is one possible outcome, but it is only a consequence of the underlying impact: arbitrary code execution. The option is too narrow and also imprecise about privilege context—code runs under the Java application's OS user, which is not necessarily the interactive 'current user,' and an attacker might execute a single command or file operation instead of spawning a full shell.

  • ✓

    The tester will be able to execute arbitrary commands on the server.

    Why this is correct

    Exploiting insecure Java deserialization typically allows an attacker to supply a specially crafted serialized object that, when deserialized, triggers a gadget chain to execute arbitrary OS commands. This is remote code execution (RCE), which is the correct and complete characterization of the vulnerability's impact, surpassing the other options in scope.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.