Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is targeting a web…

A penetration tester is targeting a web application that uses parameterized queries for all database interactions. Which attack vector is most likely to succeed?

⚠ Common exam trap

It's easy for candidates to assume parameterized queries eliminate all database-related attacks, overlooking that business logic flaws are independent of query construction and remain a viable attack vector.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business logic flaws

Parameterized queries prevent SQL injection by separating SQL code from user input, making option B ineffective. Business logic flaws (D) are vulnerabilities in the application's design or workflow that are not mitigated by secure coding practices like parameterized queries, so they remain exploitable. This attack vector targets the intended functionality of the application, such as manipulating pricing or bypassing authentication steps, which parameterized queries do not protect against.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site request forgery

    Why it's wrong here

    CSRF attacks trick an authenticated user's browser into sending crafted HTTP requests, exploiting the automatic inclusion of session cookies. Parameterized queries govern SQL statement construction and do not authenticate the origin or intent of a request. An application can have fully parameterized SQL yet still be vulnerable to CSRF if it lacks anti-CSRF tokens or SameSite cookie restrictions. Thus, CSRF is a request-forgery issue, not a query-building issue, and is not the primary target when the application uses safe database access.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection succeeds when untrusted input is concatenated directly into SQL statements, allowing an attacker to manipulate query syntax. Parameterized queries (or prepared statements) separate SQL code from data so that user input is always treated as literal data, which effectively neutralizes this class of attack. Since the application is known to use parameterization, typical SQL injection payloads would not alter query logic, so any residual vulnerability is not SQL injection. Therefore, this option is incorrect because parameterized queries directly address SQLi.

  • ✗

    Cross-site scripting

    Why it's wrong here

    Cross-site scripting arises from improper output encoding when user-controlled data is rendered in HTML, JavaScript, or other browser contexts, allowing execution of malicious script. Parameterized queries only affect how data is sent to the database; they have no role in how that data is later encoded in server responses. An application could correctly parameterize all SQL queries yet still reflect or store unsanitized input, leading to XSS. Thus, XSS is an output-side vulnerability independent of query parameterization, making it an incorrect answer.

  • ✓

    Business logic flaws

    Why this is correct

    Business logic flaws involve abusing an application's intended features and workflows, such as modifying a price field, bypassing a mandatory step, or escalating privileges by tampering with state. Parameterized queries only ensure that database input is treated as data, but they do not enforce any business rules, authorization checks, or transactional invariants. An attacker can exploit these logical weaknesses through otherwise legitimate requests, even when all SQL access is safe. This is the correct answer because query parameterization offers no protection at the application logic layer, and the tester is likely hunting for such flaws.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.