Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A penetration tester is reviewing a Java application for insecure deserialization vulnerabilities. Which of the following should the tester look for? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accepting serialized objects from user input without sanitization

Insecure deserialization vulnerabilities often arise from using ObjectInputStream without filtering and from accepting serialized data from untrusted sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Accepting serialized objects from user input without sanitization

    Why this is correct

    The application's deserialization endpoint accepts a raw byte stream from the client and reconstructs objects without any validation or integrity check. An attacker can craft a malicious serialized payload containing a 'gadget chain' of existing library classes, causing the JVM to execute arbitrary commands during object reconstruction. Sanitizing the raw bytes or validating the incoming object's class hierarchy is essential; without it, the attack surface is fully exposed.

  • ✗

    Use of eval() functions

    Why it's wrong here

    Using eval() methods (such as javax.script.ScriptEngine.eval() or expression-language evaluators) executes dynamically constructed strings as code, enabling command/expression injection if attacker-controlled input reaches it. However, this is an injection/RCE vulnerability in its own right, not an insecure deserialization flaw; it does not involve converting a serialized object graph back into live Java objects. The question specifically targets deserialization, so eval() is a wrong choice.

  • ✗

    Hardcoded credentials in configuration files

    Why it's wrong here

    Storing hardcoded credentials in configuration files is a secrets-management issue: it exposes passwords or API keys to anyone with file access, and stolen credentials can be leveraged directly against production systems. While serious, this vulnerability has no connection to Java object deserialization or how the application processes untrusted input streams. The appropriate remediation would involve secure secret storage or environment variables, not serialization filtering.

  • ✗

    Use of prepared statements for SQL queries

    Why it's wrong here

    Using prepared statements for SQL queries is a textbook defensive measure that parameterizes input and prevents SQL injection by separating SQL logic from user data. This behavior is secure and encouraged, as it eliminates the possibility of arbitrary query manipulation. Prepared statements have nothing to do with object input handling, so they neither cause nor reveal a deserialization weakness; thus this option is incorrect.

  • ✓

    Use of ObjectInputStream without validation

    Why this is correct

    When code calls readObject() on an ObjectInputStream fed by untrusted data, the JVM instantiates the class named in the stream and executes any custom readObject() methods or field setters it contains, potentially triggering gadget chains. Without a class allowlist or an ObjectInputFilter, the stream can specify dangerous classes that chain into remote code execution. This is the low-level API manifestation of the same deserialization flaw, making it a correct answer.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.