hardMultiple Choice
PT0-002 Practice Question: A penetration tester is targeting a web…
A penetration tester is targeting a web application that uses parameterized queries for all database interactions. Which attack vector is most likely to succeed?
⚠ Common exam trap
It's easy for candidates to assume parameterized queries eliminate all database-related attacks, overlooking that business logic flaws are independent of query construction and remain a viable attack vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business logic flaws
Parameterized queries prevent SQL injection by separating SQL code from user input, making option B ineffective. Business logic flaws (D) are vulnerabilities in the application's design or workflow that are not mitigated by secure coding practices like parameterized queries, so they remain exploitable. This attack vector targets the intended functionality of the application, such as manipulating pricing or bypassing authentication steps, which parameterized queries do not protect against.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site request forgery
Why it's wrong here
CSRF attacks trick an authenticated user's browser into sending crafted HTTP requests, exploiting the automatic inclusion of session cookies. Parameterized queries govern SQL statement construction and do not authenticate the origin or intent of a request. An application can have fully parameterized SQL yet still be vulnerable to CSRF if it lacks anti-CSRF tokens or SameSite cookie restrictions. Thus, CSRF is a request-forgery issue, not a query-building issue, and is not the primary target when the application uses safe database access.
- ✗
SQL injection
Why it's wrong here
SQL injection succeeds when untrusted input is concatenated directly into SQL statements, allowing an attacker to manipulate query syntax. Parameterized queries (or prepared statements) separate SQL code from data so that user input is always treated as literal data, which effectively neutralizes this class of attack. Since the application is known to use parameterization, typical SQL injection payloads would not alter query logic, so any residual vulnerability is not SQL injection. Therefore, this option is incorrect because parameterized queries directly address SQLi.
- ✗
Cross-site scripting
Why it's wrong here
Cross-site scripting arises from improper output encoding when user-controlled data is rendered in HTML, JavaScript, or other browser contexts, allowing execution of malicious script. Parameterized queries only affect how data is sent to the database; they have no role in how that data is later encoded in server responses. An application could correctly parameterize all SQL queries yet still reflect or store unsanitized input, leading to XSS. Thus, XSS is an output-side vulnerability independent of query parameterization, making it an incorrect answer.
- ✓
Business logic flaws
Why this is correct
Business logic flaws involve abusing an application's intended features and workflows, such as modifying a price field, bypassing a mandatory step, or escalating privileges by tampering with state. Parameterized queries only ensure that database input is treated as data, but they do not enforce any business rules, authorization checks, or transactional invariants. An attacker can exploit these logical weaknesses through otherwise legitimate requests, even when all SQL access is safe. This is the correct answer because query parameterization offers no protection at the application logic layer, and the tester is likely hunting for such flaws.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.