PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester is reviewing a Python script used for a custom exploit. Which of the following code snippets contains a dangerous function that could lead to remote code execution?
⚠ Common exam trap
CompTIA often tests the misconception that `input()` in Python 3 is dangerous like Python 2's `input()`, or that `subprocess.run` with a list is automatically safe, when the real danger is `eval()` and its equivalents (`exec()`, `compile()`).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
eval(user_input)
The `eval()` function in Python interprets and executes the string passed to it as a Python expression. If an attacker can control the `user_input` string, they can inject arbitrary Python code, leading to remote code execution (RCE). This is a classic dangerous function in Python that should never be used with untrusted input.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
input('Enter name:')
Why it's wrong here
input() merely reads a line from standard input; it evaluates nothing in Python 3, so no code executes. It tempts testers recalling Python 2, where input() ran eval() on the entered string, which was genuinely dangerous; the Python 3 equivalent risk sits in eval() or exec().
- ✗
open(filename, 'r')
Why it's wrong here
open() only reads or writes file content and executes nothing, so it cannot yield remote code execution. It tempts reviewers scanning for file handling, since unsafe paths enable traversal, but that is a file-disclosure risk; eval() or exec() on untrusted input is the actual RCE vector.
- ✓
eval(user_input)
Why this is correct
eval() executes its argument as Python code, so attacker-controlled input runs arbitrary commands on the host. This is the dangerous function enabling remote code execution, unlike safer alternatives such as int() or json.loads(), which parse data without executing it.
- ✗
subprocess.run(['ls'])
Why it's wrong here
subprocess.run(['ls']) executes a fixed argument list with no shell, so no attacker-controlled string reaches an interpreter. It tempts reviewers because subprocess spawns processes, but that is command execution only when shell=True or unsanitised input is passed; eval() on untrusted data is the RCE flaw.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.