Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester is tasked with exploiting a…

A penetration tester is tasked with exploiting a web application that uses an insecure deserialization vulnerability. Which type of attack should the tester primarily use to execute arbitrary code on the server?

⚠ Common exam trap

CompTIA often tests the misconception that insecure deserialization is a form of injection (like SQLi or XSS), but the key distinction is that the attack exploits the deserialization process itself, not input validation or user-triggered actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Malicious object deserialization

Insecure deserialization vulnerabilities occur when an application deserializes untrusted data without proper validation, allowing an attacker to manipulate serialized objects. By crafting a malicious object (e.g., a PHP gadget chain or a Java serialized object with a custom readObject() method), the tester can trigger arbitrary code execution on the server during the deserialization process. This directly aligns with option C, as the attack vector is the deserialization of a malicious object.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting (XSS) is a client-side injection flaw where attacker-supplied scripts are rendered by the victim's browser, executing in the same origin as the vulnerable web application. It cannot achieve server-side code execution because it solely manipulates the Document Object Model and makes HTTP requests on behalf of the user. Deserialization attacks, in contrast, target the server-side process that reconstructs objects from attacker-controlled byte streams, leading to code execution on the host.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection is a server-side attack that subverts database queries by inserting malicious SQL fragments into input parameters, permitting data exfiltration, authentication bypass, or file system read/write via database features. It does not involve object serialization or the object life-cycle; it targets the data layer and query parser directly. Unlike deserialization, SQL injection does not require the application to instantiate arbitrary classes or invoke language-specific magic methods.

  • ✓

    Malicious object deserialization

    Why this is correct

    Malicious object deserialization is the correct detection; insecure deserialization occurs when an application deserializes untrusted data without validation. An attacker supplies a crafted serialized payload that, when reconstructed, instantiates dangerous classes or invokes magic methods (e.g., __wakeup, __destruct) as part of a gadget chain, leading to arbitrary code execution, denial of service, or privilege escalation. This directly matches the scenario of exploiting a web application by sending a specially crafted object.

  • ✗

    Cross-site request forgery (CSRF)

    Why it's wrong here

    Cross-site request forgery (CSRF) is a vulnerability that forces an authenticated user's browser to send forged HTTP requests, thereby executing unintended state-changing actions on a web application. It does not achieve code execution because it simply leverages the user's existing session cookies; the attacker never sends a payload to the server. CSRF exploits trust in the user's session, whereas deserialization exploits trust in object data itself, making it a fundamentally different attack vector.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.