PT0-002 Attacks and Exploits Practice Question
A penetration tester is conducting a web application test and finds a parameter that is vulnerable to XXE. Which THREE of the following actions can the tester perform using XXE?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cause a denial of service
XXE can read files, perform SSRF, and cause denial of service. SQL injection is not typically a direct result of XXE.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Execute SQL injection
Why it's wrong here
XXE is a server-side XML parsing vulnerability that abuses the parser's handling of external entities, whereas SQL injection exploits unsanitized input concatenated into SQL queries. An XXE payload operates at the XML layer and cannot directly alter or inject SQL statements because it never manipulates query syntax or database commands. Even if an attacker reads a database configuration file or credentials, that does not constitute executing SQL injection—it simply enables a separate attack later.
- ✓
Cause a denial of service
Why this is correct
XXE can be weaponized for denial of service through entity expansion attacks, most famously the 'billion laughs' attack, in which nested entity references recursively expand to an exponentially large amount of memory or CPU usage. A single small request can exhaust available memory, crash the XML parser, or hang the application, requiring no authentication. Because these payloads are simple XML documents, they can be repeatedly sent by an unprivileged attacker, making resource exhaustion a primary and direct impact of XXE.
- ✓
Read sensitive files from the server
Why this is correct
If the XML parser resolves external entities, an attacker can define an entity that references a local file using the file:// scheme and have the file's contents rendered in the application's response or silently exfiltrated via an out-of-band channel. This allows reading arbitrary files from the web server's filesystem, such as source code, configuration files, or private keys. The file content must be parseable as text, but even binary or sensitive data can be exfiltrated using blind XXE techniques with a malicious external DTD.
- ✓
Perform SSRF to internal services
Why this is correct
XXE can be leveraged for SSRF by pointing an external entity to an internal URL, such as http://169.254.169.254/latest/meta-data/ or http://internal-admin/. The server fetches that URL during XML parsing, acting as an unwitting proxy, which lets the attacker probe internal services that are not publicly reachable. Responses can be reflected in the XML output, or attackers can use timing and error messages to infer open ports and access internal APIs without ever connecting directly.
- ✗
Bypass authentication
Why it's wrong here
Although XXE might indirectly assist with authentication bypass by leaking password hashes or session tokens via file reads or SSRF, it does not directly circumvent authentication mechanisms such as login forms, session validation, or access control checks. Bypassing authentication requires a separate vulnerability like SQL injection in a login query, session fixation, or an IDOR flaw—none of which are intrinsic to XML parser misconfiguration. The scope of XXE is limited to what external entities allow: file disclosure, resource exhaustion, and server-side requests, not alteration of authentication logic.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.