mediumMultiple Choice
PT0-002 Practice Question: A penetration tester discovers a web application…
A penetration tester discovers a web application that deserializes user-controlled data without validation. The application uses Java serialization. The tester creates a malicious serialized object that executes a system command. Which of the following conditions is required for this exploit to succeed?
⚠ Common exam trap
CompTIA often tests the misconception that privilege escalation (root) or custom class loading is required, when in fact the core requirement is the availability of gadget chains in the classpath.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Java runtime must have a gadget chain available in its classpath
Java deserialization exploits rely on the presence of specific classes (gadget chains) in the application's classpath that can be chained together to achieve arbitrary code execution. The attacker crafts a serialized object that, when deserialized, triggers a sequence of method calls (gadget chain) that ultimately executes a system command. Without a suitable gadget chain available in the classpath, the deserialization of a malicious object will not lead to code execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application must be running with root privileges
Why it's wrong here
The application's effective user ID determines the privilege level of the spawned process, but Java deserialization exploits operate entirely within the JVM's security context. Although root would expand the blast radius of a successful exploit, the gadget chain triggers code execution with whatever privileges the JVM runs under—typically the web application's service account. Requiring root is a common misconception because many believe OS-level privilege escalation is necessary, but the deserialization vulnerability itself is a logic flaw in the application's object instantiation, independent of the OS account. Thus, an unprivileged JVM can still be fully compromised, making root a condition that increases impact, not a prerequisite for exploitation.
- ✗
The application must use a custom ClassLoader
Why it's wrong here
A custom ClassLoader is an advanced Java mechanism used to load classes from non-standard sources, but it is not needed for deserialization-based code execution. The attack leverages classes already present on the application's classpath, which are loaded by the default system ClassLoader (AppClassLoader) or the application's existing loaders. The exploit chain constructs a serialized stream that causes the JVM to instantiate and invoke methods on those existing classes, such as those in Apache Commons Collections, without any custom loading logic. Therefore, requiring a custom ClassLoader confuses the deployment environment with the attack's dependency on available gadget classes; the attacker only needs the default class loading to resolve the gadget chain.
- ✓
The Java runtime must have a gadget chain available in its classpath
Why this is correct
The correct precondition for a successful Java deserialization attack is the presence of one or more gadget chains—sequences of existing classes with methods that, when invoked through crafted serialized objects, perform dangerous operations like executing commands. These chains are typically found in popular third-party libraries such as Apache Commons Collections, Commons Beanutils, or Spring, which are on the application's classpath (including nested JARs or dependency directories). The runtime must be able to resolve these classes when the serialized stream triggers their methods; without them, the deserializer may only throw exceptions or create benign objects. This is why the classpath composition is the decisive factor, not OS-specific behavior, and why penetration testers aggressively enumerate dependencies to identify exploitable gadget libraries.
- ✗
The application must be running on a Windows operating system
Why it's wrong here
Java's deserialization vulnerability is platform-independent because the JVM abstracts the underlying operating system, and gadget chains rely purely on Java class loading and method invocation. The same malicious serialized payload can execute on Windows, Linux, or macOS as long as the required library classes are present. OS-specific details like file paths or shell syntax are handled within the gadget chain itself (e.g., using Runtime.exec with a command string), but the deserialization mechanism does not depend on Windows APIs or process management. Thus, assuming Windows is necessary is a false heuristic; the attack surface is determined by the Java application's dependencies, not the host OS.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.