PT0-002 Attacks and Exploits Practice Question
A penetration tester is exploiting a web application and discovers an XML External Entity (XXE) vulnerability. Which TWO attacks can be performed using XXE?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server-Side Request Forgery (SSRF)
XXE can be used to read local files via external entities and also to perform SSRF by making the server request internal resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remote code execution
Why it's wrong here
While XXE can sometimes be escalated to remote code execution if the XML parser supports PHP or other wrappers and auxiliary functionality like file upload exists, it is not a direct or guaranteed outcome of the vulnerability. RCE requires chaining XXE with additional bugs such as insecure deserialization or write permissions to the web root. In a standard XXE scenario, the impact is limited to file disclosure or SSRF, not arbitrary command execution.
- ✗
Cross-Site Scripting (XSS)
Why it's wrong here
Cross-Site Scripting (XSS) is a client-side vulnerability where attacker-controlled data is rendered in a user's browser, executing JavaScript in the victim's session. In contrast, XXE occurs entirely on the server during XML parsing, allowing the attacker to read files or make server-side requests. While an XXE file read could theoretically be reflected in a page and later lead to stored XSS, that would be a secondary, indirect consequence, not the core mechanism or direct classification of the XXE attack.
- ✓
Server-Side Request Forgery (SSRF)
Why this is correct
Server-Side Request Forgery (SSRF) is a direct impact of XXE because an attacker can define an external entity that points to an internal URL, forcing the server's XML parser to fetch that URL on the attacker's behalf. This lets the attacker scan internal network segments, access cloud instance metadata (e.g., IAM credentials), or interact with internal services that are not exposed externally. The server's outbound request is the core of the XXE attack, making SSRF a primary and correct classification.
- ✗
SQL injection
Why it's wrong here
SQL injection (SQLi) abuses a lack of parameterization in SQL queries by injecting SQL syntax into user input, targeting the database layer directly. XXE, on the other hand, exploits an insecure <!ENTITY> declaration in an XML parser to influence file resolution and HTTP requests, not query structure. They are orthogonal vulnerability classes; identifying XXE does not imply SQLi, and fixing SQLi would not affect XXE.
- ✓
File read
Why this is correct
File read is a classic XXE outcome, achieved by defining an external entity with a file protocol path (e.g., file:///etc/passwd) and referencing that entity in an XML element that is echoed back in the HTTP response. The XML parser's built-in entity resolution loads the local file contents, which are then displayed to the attacker. This makes arbitrary file disclosure a direct, reliable impact of many XXE vulnerabilities, especially when the parser supports the file:// scheme and does not restrict external entities.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.