Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A tester is exploiting a web application and identifies a parameter that reflects user input in the response without sanitization. The tester wants to steal session cookies from other users. Which type of cross-site scripting (XSS) attack should the tester use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reflected XSS

Reflected XSS occurs when input is immediately reflected in the response. Stored XSS persists on the server. DOM-based XSS occurs client-side. For stealing cookies, reflected XSS can be crafted into a link sent to the victim.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stored XSS

    Why it's wrong here

    Stored XSS is incorrect because the payload would be permanently saved on the server (e.g., in a database, comment field, or profile) and executed whenever any user loads that stored content. In the scenario, the tester observes the injected input immediately echoed in the current HTTP response, which indicates a temporary, request-bound reflection rather than a persistent server-side persistence. Stored XSS also typically affects multiple users over time, whereas a reflected attack only triggers when the crafted link is clicked.

  • ✗

    Blind XSS

    Why it's wrong here

    Blind XSS is incorrect because the payload fires in a location the attacker cannot directly see, such as an admin panel, support ticket system, or log viewer, rather than being immediately reflected back to the attacker in the same HTTP response. Here, the tester directly sees the injected code echo in the response, so the output location is not hidden or deferred. Blind XSS usually requires an external callback (e.g., an HTTP request to an attacker-controlled server) to confirm execution, which is not described in this case.

  • ✓

    Reflected XSS

    Why this is correct

    Reflected XSS is correct because the injected script is included in a request (commonly a URL parameter) and the server immediately echoes it back in the response without proper sanitization, causing the browser to execute it. The attacker can craft a malicious link containing the payload and trick the victim into clicking it; when the victim's browser sends the request, the reflected payload executes in the victim's session. This matches the scenario where the tester exploits the web application and sees the payload reflected directly in the response, making a crafted link the natural delivery vector.

  • ✗

    DOM-based XSS

    Why it's wrong here

    DOM-based XSS is incorrect because the vulnerability would be triggered purely on the client side, where JavaScript reads data from a source like location.search or document.referrer and passes it to a sink such as innerHTML, without the server ever reflecting the payload in the response body. In this case, the tester sees the input reflected in the server's HTTP response, proving that the server-side code is directly echoing the unsanitized value. DOM-based XSS would show the payload only in the browser's DOM after client-side script execution, not in the raw server response.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.