Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is performing a vulnerability assessment of a web application. The tester wants to identify input validation vulnerabilities that could lead to injection attacks. Which two techniques are most effective for discovering injection flaws such as SQL injection and command injection? (Choose two.)

⚠ Common exam trap

The trap here is selecting source code review, which is effective but not always available in a penetration test, or selecting unrelated techniques like port scanning or password attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fuzzing input fields with a variety of special characters and payloads

Fuzzing input fields and using a web proxy to manipulate requests are both active testing techniques that directly probe the application's input handling. They allow the tester to send malicious payloads and observe if the application improperly processes them, leading to injection. These methods are effective in black-box testing scenarios where source code is not available. They are standard practices in web application penetration testing for uncovering injection vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Fuzzing input fields with a variety of special characters and payloads

    Why this is correct

    Fuzzing involves sending unexpected or malformed data to input fields to observe how the application handles it. For injection flaws, sending characters like single quotes, double quotes, semicolons, and command separators can trigger errors or unexpected behavior. This technique is effective for discovering SQL injection, command injection, and other injection vulnerabilities because it tests the application's input sanitization. It is a core method in dynamic application security testing.

  • ✓

    Using a web proxy to intercept and manipulate requests with injection payloads

    Why this is correct

    A web proxy like Burp Suite or OWASP ZAP allows the tester to intercept HTTP requests, modify parameters, and inject payloads. This is highly effective for discovering injection flaws because it provides fine-grained control over the data sent to the server. The tester can systematically test each parameter with various payloads and observe responses. This method is standard in web application penetration testing for identifying SQL injection, command injection, and similar vulnerabilities.

  • ✗

    Performing a dictionary attack against authentication mechanisms

    Why it's wrong here

    A dictionary attack targets weak passwords and is unrelated to input validation vulnerabilities. It does not test how the application handles malicious input in parameters. Injection flaws require sending crafted input to application endpoints, not guessing credentials. This technique would not help in discovering SQL injection or command injection.

  • ✗

    Reviewing the application's source code for improper input sanitization

    Why it's wrong here

    Source code review is a white-box technique that can identify potential injection flaws by examining how input is handled. However, in a penetration test, the tester often does not have access to the source code. The scenario does not specify that source code is available. While code review is effective, it is not a black-box technique and may not be feasible. The question asks for techniques most effective in a typical penetration testing context, where the tester interacts with the running application.

  • ✗

    Running a port scan to identify open ports and services

    Why it's wrong here

    Port scanning identifies network services but does not test application input validation. It is a reconnaissance step, not a technique for discovering injection flaws. While knowing open ports is useful, it does not directly reveal SQL injection or command injection vulnerabilities. The tester needs to interact with the application's input vectors, not just enumerate services.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.