PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is conducting a vulnerability assessment of a Linux web server. The tester runs a scan with Nikto and receives a finding indicating that the server is potentially vulnerable to a cross-site scripting (XSS) attack on a specific parameter. To confirm the finding, the tester wants to manually verify the XSS vulnerability. Which action should the tester take?
⚠ Common exam trap
The trap here is relying on other automated tools or scans to confirm XSS, when manual injection with a harmless payload is the definitive verification method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a web browser to inject a benign script payload into the parameter and observe if it executes
To confirm an XSS vulnerability, the tester must inject a script payload into the vulnerable parameter and observe if it executes in the context of the application. This manual verification is crucial because automated scanners like Nikto can produce false positives. Using a browser or an intercepting proxy to inject a benign alert script is the most direct and reliable method. It confirms that the application fails to sanitize input and that the payload is reflected or stored and executed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a SQL injection tool like sqlmap to test the parameter for injection flaws
Why it's wrong here
sqlmap is designed for SQL injection, not XSS. While some tools can detect multiple vulnerability types, sqlmap specifically targets SQL injection. Using it would not confirm XSS and might produce misleading results. The tester should use a method tailored to XSS, such as manual payload injection.
- ✗
Run a full port scan with Nmap to check for open ports related to the web service
Why it's wrong here
A port scan identifies open ports and services but does not verify XSS vulnerabilities. XSS is an application-layer issue that requires interacting with the web application's input handling. Port scanning is irrelevant to confirming XSS. The tester already knows the web server is running; the focus should be on the specific parameter.
- ✗
Perform a directory brute-force with Gobuster to find hidden files
Why it's wrong here
Directory brute-forcing discovers hidden files and directories but does not test for XSS. It is useful for content discovery, not for validating input validation flaws. The XSS finding is about a specific parameter, so the tester needs to interact with that parameter, not enumerate directories. This action would not confirm the XSS vulnerability.
- ✓
Use a web browser to inject a benign script payload into the parameter and observe if it executes
Why this is correct
Manual verification of XSS involves injecting a harmless script, such as <script>alert(1)</script>, into the vulnerable parameter and checking if the browser executes it. This confirms the vulnerability without causing harm. In this scenario, the tester should use a browser or proxy to inject the payload and observe the response. This is the standard method to validate XSS findings.
Go deeper
Related to this question
Learn chapter
Burp Suite for Web Application Testing
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
Nikto
Nikto is an open-source web server scanner that tests for potentially dangerous files, outdated server software, and configuration issues.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.