Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is analyzing a Bash script…

A penetration tester is analyzing a Bash script that uses 'curl' to send HTTP requests with payloads and checks for a specific string in the response. The script contains: 'if echo $response | grep -q "root:x:0:0"'. Which vulnerability is the script most likely testing for?

⚠ Common exam trap

Many candidates confuse the presence of a specific string in the response with SQL injection (e.g., thinking 'root:x:0:0' is a database record), but the format is a direct match for the /etc/passwd file, which is a classic LFI indicator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Local file inclusion

The script checks for the string 'root:x:0:0' in the HTTP response, which is the standard format of the root user entry in the /etc/passwd file on Unix-like systems. This indicates the script is testing whether the server is returning the contents of a local file (e.g., /etc/passwd) via a path traversal or file inclusion vulnerability, making Local File Inclusion (LFI) the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection (SQLi) exploits poor input validation in database queries, letting an attacker alter SQL statements to extract database contents, bypass authentication, or execute database-level functions. It is a server-side database vulnerability rather than a file system access primitive; while MySQL's LOAD_FILE() could read files if enabled and privileges permit, typical /etc/passwd disclosure via a curl request is not indicative of SQLi. The script's behavior of directly fetching a file path points to a file inclusion flaw, not interaction with a database query layer.

  • ✓

    Local file inclusion

    Why this is correct

    Local File Inclusion (LFI) occurs when a web application uses user-controlled input in file operations such as PHP's include() without proper sanitization. By supplying traversal sequences like ../../../../etc/passwd, an attacker forces the server to read and emit local file contents. The response containing 'root:x:0:0' confirms the server is outputting the /etc/passwd file, making LFI the correct classification for this curl-based test.

  • ✗

    Cross-site scripting

    Why it's wrong here

    Cross-site scripting (XSS) is a client-side injection attack that delivers malicious JavaScript to another user's browser, executing within the application's origin to steal cookies, redirect users, or alter page content. XSS does not cause the server to read files from its own filesystem; a curl request that returns /etc/passwd data indicates server-side file disclosure, not script reflection. The observed raw file content and lack of a browser-execution context rule out XSS, which would manifest as a payload echoed or rendered in a victim's browser.

  • ✗

    Remote code execution

    Why it's wrong here

    Remote code execution (RCE) allows an attacker to run arbitrary OS commands on the server, typically via command injection, unsafe deserialization, or a vulnerable function like eval(). Although 'cat /etc/passwd' could be a command an RCE test executes, the described curl script appears to manipulate a file inclusion parameter rather than a command execution input. RCE verification usually relies on executing a unique command such as 'id' or 'whoami' and observing its output, whereas reading a static file like /etc/passwd is more consistent with LFI unless further chaining is demonstrated.

Go deeper

Related to this question

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.