mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is performing a…
A penetration tester is performing a vulnerability scan of a network and finds that one server is running an outdated version of OpenSSL. Which of the following is the most likely security implication of this finding?
⚠ Common exam trap
It's easy for candidates to confuse 'buffer overflow' (a write-based code execution vulnerability) with 'buffer over-read' (a read-based information disclosure like Heartbleed), leading them to select option C instead of the more specific and correct answer D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The server is vulnerable to Heartbleed
Outdated versions of OpenSSL, particularly versions 1.0.1 through 1.0.1f, are vulnerable to the Heartbleed bug (CVE-2014-0160). This vulnerability allows an attacker to read up to 64 KB of memory from the server's heap, potentially exposing private keys, session tokens, and other sensitive data. The Heartbleed bug is a specific buffer over-read vulnerability in the TLS/DTLS heartbeat extension, making D the correct answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server is vulnerable to SQL injection
Why it's wrong here
SQL injection is an application-layer vulnerability that arises from unvalidated user input being concatenated into database queries, typically in web-facing code such as PHP or ASP.NET. An OpenSSL vulnerability scanner reports flaws in the TLS/SSL cryptographic library based on version banners or protocol responses, not the application's database handler. Therefore, a scanner flag related to OpenSSL would not be labeled as SQL injection, as the two issues affect entirely different components of the server stack.
- ✗
The server is vulnerable to cross-site scripting
Why it's wrong here
Cross-site scripting (XSS) involves an attacker injecting client-side scripts into web pages, exploiting insufficient output encoding in the application's rendering logic. Since OpenSSL operates strictly at the transport layer, encrypting and decrypting network traffic without any awareness of HTML or JavaScript, a vulnerability scan of an OpenSSL service cannot produce an XSS finding. The scan would target the TLS implementation itself, not the web application's input validation or output encoding mechanisms.
- ✗
The server is vulnerable to buffer overflow
Why it's wrong here
Although OpenSSL has historically contained buffer overflow flaws, the specific vulnerability being tested here is Heartbleed (CVE-2014-0160), which is an out-of-bounds read, not a classic buffer overflow that enables code execution. A standard buffer overflow involves writing beyond an allocated buffer, potentially leading to remote code execution, whereas Heartbleed leaks memory contents via an overly large length field in the heartbeat request. Vulnerability scanners identify the exact CVE based on the service version; they would report Heartbleed as an information-disclosure flaw rather than a generic buffer overflow.
- ✓
The server is vulnerable to Heartbleed
Why this is correct
The server is vulnerable to Heartbleed, a serious flaw in OpenSSL 1.0.1 through 1.0.1f, tracked as CVE-2014-0160. The vulnerability resides in the TLS heartbeat extension, where a missing bounds check allows an attacker to send a malformed heartbeat request with an oversized payload length, causing the server to return up to 64KB of its memory, which may include private keys and user credentials. This flaw is uniquely tied to OpenSSL and was widely exploited in 2014, making it the default finding when a scanner detects an affected OpenSSL version.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.