mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is analyzing a Bash script…
A penetration tester is analyzing a Bash script that uses 'curl' to send HTTP requests with payloads and checks for a specific string in the response. The script contains: 'if echo $response | grep -q "root:x:0:0"'. Which vulnerability is the script most likely testing for?
⚠ Common exam trap
Many candidates confuse the presence of a specific string in the response with SQL injection (e.g., thinking 'root:x:0:0' is a database record), but the format is a direct match for the /etc/passwd file, which is a classic LFI indicator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local file inclusion
The script checks for the string 'root:x:0:0' in the HTTP response, which is the standard format of the root user entry in the /etc/passwd file on Unix-like systems. This indicates the script is testing whether the server is returning the contents of a local file (e.g., /etc/passwd) via a path traversal or file inclusion vulnerability, making Local File Inclusion (LFI) the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection
Why it's wrong here
SQL injection (SQLi) exploits poor input validation in database queries, letting an attacker alter SQL statements to extract database contents, bypass authentication, or execute database-level functions. It is a server-side database vulnerability rather than a file system access primitive; while MySQL's LOAD_FILE() could read files if enabled and privileges permit, typical /etc/passwd disclosure via a curl request is not indicative of SQLi. The script's behavior of directly fetching a file path points to a file inclusion flaw, not interaction with a database query layer.
- ✓
Local file inclusion
Why this is correct
Local File Inclusion (LFI) occurs when a web application uses user-controlled input in file operations such as PHP's include() without proper sanitization. By supplying traversal sequences like ../../../../etc/passwd, an attacker forces the server to read and emit local file contents. The response containing 'root:x:0:0' confirms the server is outputting the /etc/passwd file, making LFI the correct classification for this curl-based test.
- ✗
Cross-site scripting
Why it's wrong here
Cross-site scripting (XSS) is a client-side injection attack that delivers malicious JavaScript to another user's browser, executing within the application's origin to steal cookies, redirect users, or alter page content. XSS does not cause the server to read files from its own filesystem; a curl request that returns /etc/passwd data indicates server-side file disclosure, not script reflection. The observed raw file content and lack of a browser-execution context rule out XSS, which would manifest as a payload echoed or rendered in a victim's browser.
- ✗
Remote code execution
Why it's wrong here
Remote code execution (RCE) allows an attacker to run arbitrary OS commands on the server, typically via command injection, unsafe deserialization, or a vulnerable function like eval(). Although 'cat /etc/passwd' could be a command an RCE test executes, the described curl script appears to manipulate a file inclusion parameter rather than a command execution input. RCE verification usually relies on executing a unique command such as 'id' or 'whoami' and observing its output, whereas reading a static file like /etc/passwd is more consistent with LFI unless further chaining is demonstrated.
Go deeper
Related to this question
Learn chapter
CVSS Scoring in Penetration Test Reports
Key term
Path traversal
Path traversal is a web security vulnerability that allows an attacker to access files and directories stored outside the web server's root folder by manipulating file paths in user-supplied input.
Key term
Bash script
A Bash script is a text file containing a sequence of commands for the Unix shell Bash, allowing users to automate repetitive tasks and streamline system administration on Linux and macOS.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.