Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is conducting a vulnerability assessment of a Linux web server. The tester runs a scan with Nikto and receives a finding indicating that the server is potentially vulnerable to a cross-site scripting (XSS) attack on a specific parameter. To confirm the finding, the tester wants to manually verify the XSS vulnerability. Which action should the tester take?

⚠ Common exam trap

The trap here is relying on other automated tools or scans to confirm XSS, when manual injection with a harmless payload is the definitive verification method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a web browser to inject a benign script payload into the parameter and observe if it executes

To confirm an XSS vulnerability, the tester must inject a script payload into the vulnerable parameter and observe if it executes in the context of the application. This manual verification is crucial because automated scanners like Nikto can produce false positives. Using a browser or an intercepting proxy to inject a benign alert script is the most direct and reliable method. It confirms that the application fails to sanitize input and that the payload is reflected or stored and executed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a SQL injection tool like sqlmap to test the parameter for injection flaws

    Why it's wrong here

    sqlmap is designed for SQL injection, not XSS. While some tools can detect multiple vulnerability types, sqlmap specifically targets SQL injection. Using it would not confirm XSS and might produce misleading results. The tester should use a method tailored to XSS, such as manual payload injection.

  • ✗

    Run a full port scan with Nmap to check for open ports related to the web service

    Why it's wrong here

    A port scan identifies open ports and services but does not verify XSS vulnerabilities. XSS is an application-layer issue that requires interacting with the web application's input handling. Port scanning is irrelevant to confirming XSS. The tester already knows the web server is running; the focus should be on the specific parameter.

  • ✗

    Perform a directory brute-force with Gobuster to find hidden files

    Why it's wrong here

    Directory brute-forcing discovers hidden files and directories but does not test for XSS. It is useful for content discovery, not for validating input validation flaws. The XSS finding is about a specific parameter, so the tester needs to interact with that parameter, not enumerate directories. This action would not confirm the XSS vulnerability.

  • ✓

    Use a web browser to inject a benign script payload into the parameter and observe if it executes

    Why this is correct

    Manual verification of XSS involves injecting a harmless script, such as <script>alert(1)</script>, into the vulnerable parameter and checking if the browser executes it. This confirms the vulnerability without causing harm. In this scenario, the tester should use a browser or proxy to inject the payload and observe the response. This is the standard method to validate XSS findings.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.