Courseiva
hardMultiple Select

PT0-002 Cross-Site Scripting (XSS) Practice Question

A tester is conducting a code review of a web application. Which three coding practices can help prevent cross-site scripting (XSS)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Content Security Policy (CSP) headers

Content Security Policy (CSP) headers (B) are correct because a restrictive CSP, such as one using default-src 'self' and disallowing 'unsafe-inline', prevents the browser from executing injected inline or third-party scripts, which is a primary XSS mitigation. Output encoding (D) is correct because encoding untrusted data for the correct context (HTML entity encoding, JavaScript escaping, URL encoding, CSS escaping) ensures attacker-supplied markup is rendered as inert text rather than executable script. Input validation (E) is correct because validating input against a strict allowlist (for example, expected format, length, and character set) rejects or sanitizes malicious payloads before they can be stored or reflected, reducing XSS attack surface. Parameterized queries (A) are not correct here because they prevent SQL injection, not XSS. Disabling JavaScript in the client (C) is not a server-side coding practice and is impractical for a web application that depends on JavaScript, so it is not a recommended XSS prevention control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Parameterized queries

    Why it's wrong here

    Parameterized queries prevent SQL injection by separating code from data in database statements; they do nothing for XSS, which requires output encoding and input validation in the browser context. They are the correct control when untrusted input reaches a SQL interpreter.

  • ✓

    Content Security Policy (CSP) headers

    Why this is correct

    CSP headers instruct the browser to load scripts only from approved sources and block inline execution, providing defence in depth when an injection slips past other controls. This constrains the impact of any reflected or stored XSS payload that reaches the rendered page.

  • ✗

    Disabling JavaScript in the client

    Why it's wrong here

    Disabling JavaScript in the client is a browser setting, not a coding practice, and cannot be enforced by the application; XSS prevention requires server-side output encoding and input validation. It is tempting as a quick mitigation, but it is unsuitable for protecting all users of a web application.

  • ✓

    Output encoding

    Why this is correct

    Output encoding converts untrusted data into safe HTML, JavaScript, or attribute representations before rendering, so injected script is treated as text rather than executed. This neutralises stored and reflected XSS at the point of display, regardless of what reached the database.

  • ✓

    Input validation

    Why this is correct

    Input validation rejects or sanitises data that does not match expected formats, lengths, and character sets at the entry point, preventing malicious payloads from being stored or reflected. Allowlist validation is preferred, since blocklists are easily bypassed by encoding tricks.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.