PT0-002 Attacks and Exploits Practice Question
A penetration tester is testing a web application and wants to exploit an XXE vulnerability to read sensitive files. Which TWO payloads could be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'http://169.254.169.254/latest/meta-data/'>]>
XXE can be used to read files via file:// or to perform SSRF to internal resources via http://, including cloud metadata.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
<script>alert(1)</script>
Why it's wrong here
The <script>alert(1)</script> payload is a classic cross-site scripting (XSS) probe that executes JavaScript in the victim's browser. It does not interact with the server's XML parser, so it cannot detect XML external entity injection. This attack targets client-side rendering and reflected/stored input, not server-side XML processing.
- ✓
<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'http://169.254.169.254/latest/meta-data/'>]>
Why this is correct
This payload defines an external entity named 'xxe' that points to the link-local cloud metadata service at 169.254.169.254. When the vulnerable XML parser resolves the entity, it performs a server-side request to that URL, allowing the tester to access instance metadata like IAM credentials. This is both an XXE and an SSRF, specifically aimed at cloud environments.
- ✓
<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'file:///etc/passwd'>]>
Why this is correct
Defining an entity that references file:///etc/passwd causes the XML parser to read the local passwd file and include its contents in the response. This works only if the parser supports the file scheme and does not disable external general entities. It demonstrates local file disclosure through XXE, which is distinct from network requests to internal systems.
- ✗
'; DROP TABLE users; --
Why it's wrong here
The input '; DROP TABLE users; -- is a SQL injection attempt that tries to terminate the current SQL statement and execute a destructive command on the database. It is unrelated to XML parsing; it targets the database layer, not the XML parser. Using this payload would not reveal XXE vulnerabilities because it doesn't involve document type declarations or entity resolution.
- ✗
../../etc/passwd
Why it's wrong here
This payload attempts a path traversal attack by using ../ sequences to navigate outside the web root to access /etc/passwd on the filesystem. It exploits the web server's file handling logic, not the XML parser's entity resolution. It is a different vulnerability class from XXE and would not trigger an external entity fetch.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.