hardMultiple Select
PT0-002 Cross-Site Scripting (XSS) Practice Question
A tester is conducting a code review of a web application. Which three coding practices can help prevent cross-site scripting (XSS)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Content Security Policy (CSP) headers
Content Security Policy (CSP) headers (B) are correct because a restrictive CSP, such as one using default-src 'self' and disallowing 'unsafe-inline', prevents the browser from executing injected inline or third-party scripts, which is a primary XSS mitigation. Output encoding (D) is correct because encoding untrusted data for the correct context (HTML entity encoding, JavaScript escaping, URL encoding, CSS escaping) ensures attacker-supplied markup is rendered as inert text rather than executable script. Input validation (E) is correct because validating input against a strict allowlist (for example, expected format, length, and character set) rejects or sanitizes malicious payloads before they can be stored or reflected, reducing XSS attack surface. Parameterized queries (A) are not correct here because they prevent SQL injection, not XSS. Disabling JavaScript in the client (C) is not a server-side coding practice and is impractical for a web application that depends on JavaScript, so it is not a recommended XSS prevention control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Parameterized queries
Why it's wrong here
Parameterized queries prevent SQL injection by separating code from data in database statements; they do nothing for XSS, which requires output encoding and input validation in the browser context. They are the correct control when untrusted input reaches a SQL interpreter.
- ✓
Content Security Policy (CSP) headers
Why this is correct
CSP headers instruct the browser to load scripts only from approved sources and block inline execution, providing defence in depth when an injection slips past other controls. This constrains the impact of any reflected or stored XSS payload that reaches the rendered page.
- ✗
Disabling JavaScript in the client
Why it's wrong here
Disabling JavaScript in the client is a browser setting, not a coding practice, and cannot be enforced by the application; XSS prevention requires server-side output encoding and input validation. It is tempting as a quick mitigation, but it is unsuitable for protecting all users of a web application.
- ✓
Output encoding
Why this is correct
Output encoding converts untrusted data into safe HTML, JavaScript, or attribute representations before rendering, so injected script is treated as text rather than executed. This neutralises stored and reflected XSS at the point of display, regardless of what reached the database.
- ✓
Input validation
Why this is correct
Input validation rejects or sanitises data that does not match expected formats, lengths, and character sets at the entry point, preventing malicious payloads from being stored or reflected. Allowlist validation is preferred, since blocklists are easily bypassed by encoding tricks.
Go deeper
Related to this question
Learn chapter
Scripting and Automation for PenTest
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
Mitigation
Mitigation is the process of reducing the severity, impact, or likelihood of a security threat or vulnerability.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.