Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

A penetration tester is conducting a web application test and discovers an XML External Entity (XXE) vulnerability. Which of the following attacks can the tester perform using XXE? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Read sensitive files from the server

XXE can be used to read files, perform SSRF, and cause denial of service via entity expansion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Read sensitive files from the server

    Why this is correct

    An XML parser allows an attacker to define an external entity, such as `<!ENTITY xxe SYSTEM "file:///etc/passwd">`. When the application processes the XML and includes the entity in a response or error message, the server reads the local file and returns its contents, disclosing credentials, configuration, or other sensitive data. This requires the parser to resolve external general entities without secure settings, a common misconfiguration in web applications.

  • ✓

    Denial of service via entity expansion (billion laughs)

    Why this is correct

    An attacker can define deeply nested entity references, e.g., the classic 'billion laughs' payload, where entities expand exponentially during parsing. Each entity references multiple copies of another, causing the parser to expand the content to enormous sizes (e.g., a few hundred bytes become billions of bytes), exhausting CPU and memory and crashing or hanging the server. This exploit targets the XML parser's entity expansion limits, which are often disabled or misconfigured.

  • ✓

    Perform Server-Side Request Forgery (SSRF)

    Why this is correct

    External entities can be set to `http://` or `https://` URIs, causing the server to make HTTP requests on the attacker's behalf. The attacker can target internal services without direct network exposure, such as AWS metadata (169.254.169.254), internal admin panels, or local-only endpoints. Responses from these internal systems may be reflected in the XML output, or the attacker can use error messages to exfiltrate data, effectively turning the XML parser into a proxy for internal network reconnaissance.

  • ✗

    SQL injection through entity values

    Why it's wrong here

    XXE occurs during XML parsing before any SQL query is built; the entity value is just a string in the parsed document. Although the application might use that string as part of a SQL query, SQL injection is a separate application-layer flaw where the query is not parameterized. Entity values are not executed as SQL automatically; a reachable SQL injection must be independently present, and XXE does not 'cause' SQL injection by itself.

  • ✗

    Remote code execution

    Why it's wrong here

    Direct RCE via XXE is not typical; it generally requires an additional feature such as PHP's `expect://` wrapper or a CJAX factory that allows file writes. In most practical scenarios, XXE impacts confidentiality and availability (file read/SSRF/DoS) but does not provide arbitrary code execution. An attacker would need to chain XXE with file upload or other vulnerabilities to achieve RCE, so it is not a core capability of XXE.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.