Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester is testing a web application and discovers an endpoint that returns XML data. The tester attempts to read /etc/passwd by injecting an external entity. Which type of attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

XXE injection

XML External Entity (XXE) injection allows reading files or performing SSRF via XML processing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    XXE injection

    Why this is correct

    XXE injection is correct because the vulnerability arises from the XML parser processing an external entity defined in the DOCTYPE declaration. An attacker can use a crafted XML payload with an entity like <!ENTITY xxe SYSTEM "file:///etc/passwd"> to read sensitive files, perform internal port scans, or trigger network requests. The root cause is the application's insecure handling of XML external entities, which is the defining characteristic of XXE.

  • ✗

    Command injection

    Why it's wrong here

    Command injection is incorrect because it involves injecting operating system commands into a vulnerable input that is passed to a system shell, typically using separators like ;, |, or $( ). The attack targets command execution contexts such as micsystem() or exec(), not the XML parsing mechanism. In this scenario, the vulnerability is triggered through XML entity processing, not through shell command injection, so classifying it as command injection would misidentify the injection point and required payload.

  • ✗

    SSRF

    Why it's wrong here

    SSRF is a plausible but incorrect answer because it describes the consequence or impact of XXE rather than the vulnerability class itself. While a malicious external entity can make the server issue HTTP requests to internal addresses (a classic SSRF effect), the primary flaw is the XML parser's acceptance of external entities. The attack vector is XML injection, so the correct label is XXE injection, not SSRF, even if SSRF is a secondary outcome.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection is wrong because it targets the database layer by injecting malicious SQL statements into parameters that are concatenated into queries, like ' OR 1=1--. The payload syntax and structural flaw are completely different: SQLi uses SQL keywords and operators, while XXE uses XML entity declarations. This vulnerability exists in XML parsing, not in database query construction, so SQL injection cannot explain the observed behavior.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.