PT0-002 Attacks and Exploits Practice Question
A penetration tester discovers a web application that fetches URLs from user input without proper validation. The tester targets the internal cloud metadata endpoint at 169.254.169.254 to retrieve instance credentials. Which type of attack is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSRF
SSRF (Server-Side Request Forgery) occurs when the server makes requests to internal resources based on user input, and the cloud metadata endpoint is a common target.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CSRF
Why it's wrong here
CSRF (Cross-Site Request Forgery) forces an authenticated browser to submit a forged request to a web application, relying on the user's session cookies for authorization. It is a client-side attack that targets state-changing requests, not a server-side URL fetching feature. Since the discovered vulnerability involves the application server retrieving external URLs, CSRF's request-forgery model does not apply.
- ✗
XXE
Why it's wrong here
XXE (XML External Entity) arises when an XML parser processes externally defined entities, allowing attackers to read local files, perform internal network scans, or even trigger SSRF via `file://` or `http://` entity URLs. However, it fundamentally requires XML input and a misconfigured parser. The discovered vulnerability is a URL-fetch endpoint that need not involve XML at all, so labeling it XXE would be inaccurate even though both can lead to server-side requests.
- ✓
SSRF
Why this is correct
SSRF (Server-Side Request Forgery) occurs when an attacker controls the URL that the server fetches, enabling requests to internal IPs, localhost, or cloud metadata services. The described web application that fetches URLs is a textbook SSRF vector: it lets the server make arbitrary outbound HTTP requests, bypassing network perimeters. This can expose internal services, credentials, or sensitive data, making SSRF the correct classification.
- ✗
IDOR
Why it's wrong here
IDOR (Insecure Direct Object Reference) happens when an application exposes direct references to internal objects, such as database record IDs or filenames, and fails to enforce authorization on those references. Exploitation means tampering with parameters to access another user's data, a form of broken access control. The scenario is not about direct object manipulation but about the server-side fetching of URLs, so IDOR is unrelated.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.