Courseiva
mediumMultiple Choice

PT0-002 Practice Question: A penetration tester is analyzing a Python script…

A penetration tester is analyzing a Python script that uses the 'subprocess' module to execute shell commands. The tester notices that the script passes user-supplied input directly to the shell without any sanitization or validation. Which vulnerability class is most likely present in this script?

⚠ Common exam trap

It's easy for candidates to confuse command injection with SQL injection because both involve untrusted input, but the key differentiator is the execution context—shell commands versus database queries—and the specific module (`subprocess`) indicates shell execution, not database interaction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command injection

The script uses the `subprocess` module to execute shell commands with user-supplied input passed directly to the shell without sanitization. This allows an attacker to inject arbitrary shell metacharacters (e.g., `;`, `|`, `&&`) to execute unintended commands, which is the classic definition of command injection. The vulnerability arises because the input is concatenated into a command string rather than passed as a list of arguments, bypassing the shell's argument separation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Command injection

    Why this is correct

    This is command injection because the script passes unsanitized user input directly to a shell interpreter. When subprocess is called with shell=True or os.system, metacharacters such as semicolons, ampersands, or pipes allow an attacker to terminate the intended command and chain arbitrary OS commands. The subprocess module's shell=True feature is a classic sink for this vulnerability, and the lack of input validation or escaping makes it exploitable for remote code execution.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection is a data-layer attack where untrusted input is concatenated into SQL queries, allowing an attacker to modify the query structure, bypass authentication, or extract database contents. It does not directly execute OS commands; while certain databases may expose extended procedures like xp_cmdshell, that requires a separate, already-writable database context. The vulnerability described here is in shell command construction, not in database query building, so SQL injection is not the applicable classification.

  • ✗

    Path traversal

    Why it's wrong here

    Path traversal, also known as directory traversal, exploits insufficient sanitization of file paths to access files or directories outside an intended root, typically using ../ sequences. This vulnerability impacts file system confidentiality and integrity but does not inherently enable arbitrary command execution. The script's flaw is that user input is used to form a shell command, not a file system path, making path traversal an incorrect characterization of the vulnerability.

  • ✗

    Buffer overflow

    Why it's wrong here

    Buffer overflow is a memory corruption vulnerability that occurs when data written to a fixed-length buffer exceeds its bounds and overwrites adjacent memory, often enabling code execution in low-level languages like C or C++. Python's runtime manages memory safely with bounds checking, and the subprocess module does not expose direct buffer manipulation. The reported vulnerability involves insecure use of a shell, not memory corruption, so buffer overflow is an incorrect explanation.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.