Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester discovers a web application that fetches URLs from user input without proper validation. The tester targets the internal cloud metadata endpoint at 169.254.169.254 to retrieve instance credentials. Which type of attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSRF

SSRF (Server-Side Request Forgery) occurs when the server makes requests to internal resources based on user input, and the cloud metadata endpoint is a common target.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CSRF

    Why it's wrong here

    CSRF (Cross-Site Request Forgery) forces an authenticated browser to submit a forged request to a web application, relying on the user's session cookies for authorization. It is a client-side attack that targets state-changing requests, not a server-side URL fetching feature. Since the discovered vulnerability involves the application server retrieving external URLs, CSRF's request-forgery model does not apply.

  • ✗

    XXE

    Why it's wrong here

    XXE (XML External Entity) arises when an XML parser processes externally defined entities, allowing attackers to read local files, perform internal network scans, or even trigger SSRF via `file://` or `http://` entity URLs. However, it fundamentally requires XML input and a misconfigured parser. The discovered vulnerability is a URL-fetch endpoint that need not involve XML at all, so labeling it XXE would be inaccurate even though both can lead to server-side requests.

  • ✓

    SSRF

    Why this is correct

    SSRF (Server-Side Request Forgery) occurs when an attacker controls the URL that the server fetches, enabling requests to internal IPs, localhost, or cloud metadata services. The described web application that fetches URLs is a textbook SSRF vector: it lets the server make arbitrary outbound HTTP requests, bypassing network perimeters. This can expose internal services, credentials, or sensitive data, making SSRF the correct classification.

  • ✗

    IDOR

    Why it's wrong here

    IDOR (Insecure Direct Object Reference) happens when an application exposes direct references to internal objects, such as database record IDs or filenames, and fails to enforce authorization on those references. Exploitation means tampering with parameters to access another user's data, a form of broken access control. The scenario is not about direct object manipulation but about the server-side fetching of URLs, so IDOR is unrelated.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.