PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is analyzing a Java application and finds the following code snippet: Object obj = ois.readObject(); where ois is an ObjectInputStream. What vulnerability is most likely present if the input is untrusted?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insecure deserialization
Insecure deserialization occurs when readObject() is called on untrusted data, potentially leading to code execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection
Why it's wrong here
SQL injection is not applicable because the described interaction with the Java application shows no evidence of database queries, JDBC calls, or string concatenation forming SQL statements. The vulnerability requires user-controlled input being interpolated into a SQL command, and without any data store interaction, the attack surface for SQLi simply does not exist. A tester investigating a Java deserialization flaw would not expect to find SQLi unless the application later uses the deserialized object to build queries, which is not indicated here.
- ✗
Path traversal
Why it's wrong here
Path traversal attacks rely on manipulating file path parameters such as '../' sequences to access files outside the intended directory. The scenario references a Java application and likely an object stream, not file I/O operations involving user-supplied filenames or paths. Without evidence of file system access, such as File, FileInputStream, or getResourceAsStream calls tied to untrusted input, path traversal cannot be the root cause. The presence of readObject() points to deserialization rather than filesystem manipulation.
- ✓
Insecure deserialization
Why this is correct
Insecure deserialization is the correct answer because the code likely invokes readObject() on an ObjectInputStream constructed from untrusted input. Attackers can craft a malicious serialized object that, when deserialized, triggers arbitrary code execution through gadget chains in the application's classpath. Java's default deserialization mechanism does not validate the object's class or state, allowing an attacker to exploit this trust boundary. The vulnerability is especially dangerous when the application does not use look-ahead object filtering or allowlist-based class checks before deserializing data.
- ✗
Cross-site scripting
Why it's wrong here
Cross-site scripting (XSS) is a client-side vulnerability that involves injecting malicious scripts into web pages rendered in a user's browser. The Java application is likely server-side logic, and the issue involves processing serialized data rather than reflecting or storing untrusted HTML/JavaScript in HTTP responses. Even if the application is a web service, XSS would require the input to be echoed into a response body, whereas deserialization occurs during object reconstruction. Thus, XSS is not the correct classification for a readObject() vulnerability.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.