hardMultiple Choice
PT0-002 Practice Question: A penetration tester discovers a web application…
A penetration tester discovers a web application that uses client-side JavaScript to validate user input before form submission. The input is then sent to the server and used directly in a SQL query without server-side validation. Which attack would most effectively exploit this vulnerability?
⚠ Common exam trap
It's easy for candidates to confuse client-side validation bypass with XSS, thinking that JavaScript injection is the primary risk, but the key is that the input flows directly into a SQL query, making SQL injection the most effective and direct attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
The vulnerability described—client-side JavaScript validation with no server-side sanitization, followed by direct use of input in a SQL query—is the classic precondition for SQL injection. An attacker can bypass client-side controls (e.g., by disabling JavaScript or using a proxy like Burp Suite) and submit crafted SQL syntax (e.g., `' OR 1=1 --`) to manipulate the query, extract data, or execute arbitrary SQL commands on the database server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SQL injection
Why this is correct
Client-side validation is only a convenience for users; a penetration tester can intercept or bypass it and submit raw HTTP requests containing malicious SQL payloads directly to the server. If the application concatenates unsanitized input into dynamic SQL queries, the tester can manipulate the query structure, for example by using UNION-based or boolean-based payloads to extract data. This directly exploits the database back end, whereas the other listed attacks do not.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
Cross-site scripting (XSS) does not exploit server-side database query logic. Instead, it involves injecting malicious JavaScript into web pages that execute in the victim's browser, typically to steal cookies, session tokens, or perform actions on behalf of the user. While an XSS payload can indirectly affect data if it triggers authenticated requests, it does not directly manipulate the SQL statement executed by the database, so it is not the correct classification for a database query vulnerability.
- ✗
Command injection
Why it's wrong here
Command injection occurs when user input is passed to an operating system command interpreter, such as cmd.exe, /bin/sh, or PowerShell, without proper sanitization. In the scenario described, the vulnerability lies in the application's interaction with a database, meaning the input is used in a SQL context, not a shell context. Injecting OS commands into a SQL query would simply produce a SQL syntax error or be treated as string data, unless a separate command execution path exists.
- ✗
Parameter pollution
Why it's wrong here
Parameter pollution, also known as HTTP parameter pollution, involves sending multiple parameters with the same name or manipulating parameter delimiters to alter how the application processes request data. This attack may cause the application to use a different parameter value or bypass certain checks, but it does not directly modify the structure of a SQL query. Since the web application is vulnerable at the database query level, the correct cause is SQL injection, not parameter pollution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.