PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing a web application assessment. Which of the following are common techniques to identify and exploit IDOR vulnerabilities? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enumerate sequential IDs in URLs
IDOR involves manipulating object references; enumeration of IDs and modifying parameter values are common techniques.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a man-in-the-middle attack
Why it's wrong here
Performing a man-in-the-middle attack involves intercepting and potentially altering traffic between the client and server at the network layer. This technique can expose session tokens or parameters but does not actively test the server's authorization checks on object references. IDOR is a server-side access-control flaw that is confirmed by submitting tampered identifiers directly to the application, not by passively observing or modifying in transit. MITM is a general transport-layer attack, not a specific discovery method for IDOR.
- ✓
Enumerate sequential IDs in URLs
Why this is correct
Enumerating sequential IDs in URLs means iterating through predictable object identifiers, such as invoice numbers or user IDs, to see if the application grants unauthorized access to resources that belong to other users. This is a core IDOR testing technique because it directly targets the lack of proper authorization on direct object references. By successfully retrieving other users' records with only a changed integer, the tester proves the access-control flaw.
- ✓
Intercept requests and modify parameter values
Why this is correct
Using an intercepting proxy like Burp Suite, the tester captures a legitimate request and then modifies parameter values—for example, changing a bank account number or document ID—before forwarding it to the server. If the server responds with data or functionality tied to the modified object without verifying the user's ownership, the application is vulnerable to IDOR. This active parameter tampering is a standard method for identifying broken object-level authorization.
- ✗
Use SQL injection to bypass authentication
Why it's wrong here
SQL injection involves injecting malicious SQL statements into input fields to manipulate database queries, often to bypass login mechanisms or retrieve arbitrary records. While this can expose sensitive data, it exploits a query-layer vulnerability, not a missing authorization check on object references. IDOR testing focuses on replacing direct object references without authentication bypass; the two are separate vulnerability classes and require different remediation.
- ✗
Inject malicious scripts into input fields
Why it's wrong here
Injecting malicious scripts into input fields is the primary test for Cross-Site Scripting (XSS), where the payload executes in a victim's browser. XSS abuses a lack of output encoding or input validation, whereas IDOR is an authorization flaw on the server. The goals and exploitation paths are distinct: XSS steals tokens or manipulates the client, while IDOR accesses unauthorized objects by ID substitution. Therefore, this action is not used to confirm IDOR.
Go deeper
Related to this question
Learn chapter
Subdomain Enumeration and Takeover
Key term
IDOR
IDOR (Insecure Direct Object Reference) is a vulnerability where an application exposes internal object references, allowing attackers to access or modify data by manipulating those references.
Key term
Enumeration
Enumeration is the systematic process of extracting detailed information about a target system, such as user accounts, network shares, services, and configurations, used during the reconnaissance phase of a security assessment.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.