PT0-002 Attacks and Exploits Practice Question
A penetration tester is attempting to exploit a server-side request forgery (SSRF) vulnerability in a cloud-hosted web application to access the cloud metadata service. Which IP address should the tester target?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
169.254.169.254
The cloud metadata service for most cloud providers (AWS, GCP, Azure) is accessible via 169.254.169.254.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
192.168.1.1
Why it's wrong here
192.168.1.1 is an RFC1918 private address that commonly serves as the default gateway on SOHO routers. It is not the cloud metadata service, which uses a reserved link-local IPv4 address. A tester targeting this IP would be probing the local router's administrative interface, not retrieving instance metadata, so it would not yield IAM credentials or cloud configurations.
- ✓
169.254.169.254
Why this is correct
169.254.169.254 is a link-local address within the 169.254.0.0/16 range, reserved by RFC 3927, and is the well-known metadata service endpoint used by major cloud providers (AWS, GCP, Azure). It is reachable only from inside the instance itself and does not require routing; an SSRF vulnerability can be leveraged to send authenticated requests to this IP to retrieve instance metadata such as IAM temporary credentials, user-data scripts, or security group configurations. This is why it is a prime target during penetration tests against web applications with server-side request forgery flaws.
- ✗
127.0.0.1
Why it's wrong here
127.0.0.1 is the loopback address that refers to the local machine's own TCP/IP stack, allowing a process to communicate with another process on the same host. While it is also non-routable like the metadata IP, accessing it will only reach services bound to localhost, such as a database or debugging endpoint, not the cloud metadata provider. The metadata service listens on a distinct link-local address, so conflating loopback with the metadata service would cause a tester to miss valid cloud credentials.
- ✗
10.0.0.1
Why it's wrong here
The cloud metadata service for major providers such as AWS, GCP, and Azure is accessed at 169.254.169.254, not 10.0.0.1. The 10.0.0.1 address is typically the default gateway for a virtual network’s subnet, so a tester might mistakenly target it when thinking of internal routing rather than the link-local metadata endpoint. In a scenario requiring exploitation of a local network gateway or router interface, 10.0.0.1 would be correct.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.