Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A tester is performing a web application test and finds an endpoint that accepts XML input. The tester sends a payload that includes an external entity referencing a local file. Which vulnerability is being tested?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

XXE

XXE (XML External Entity) injection allows reading local files or performing SSRF via XML parsers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IDOR

    Why it's wrong here

    Insecure Direct Object Reference (IDOR) occurs when an application exposes internal object identifiers, such as database keys, file names, or record IDs, in URLs or parameters without verifying the user's authorization level. Attackers can enumerate and manipulate these references to access unauthorized data. The finding here stems from XML parser behavior rather than predictable object access, so IDOR does not align with the observed vulnerability.

  • ✗

    SSRF

    Why it's wrong here

    Server-Side Request Forgery (SSRF) is a flaw that lets an attacker cause the server to make arbitrary HTTP requests to internal or external systems, often through a parameter that accepts URLs. While XXE can be chained to trigger SSRF by referencing a remote URL in an external entity, the root cause in this case is the XML parser's unsafe handling of external entities, not a general URL fetching feature. SSRF alone would not explain the direct file disclosure typically seen with XXE.

  • ✓

    XXE

    Why this is correct

    XML External Entity (XXE) injection occurs when an XML parser processes external entities defined in a DTD (Document Type Definition), allowing attackers to read local files, perform internal port scans, or cause denial of service. The 'e' in the stem strongly suggests 'external entity,' and the classic symptom is sensitive data disclosure, such as /etc/passwd or configuration files. This vulnerability arises when developers leave DTD processing and external entity resolution enabled in XML libraries, making XXE the correct finding.

  • ✗

    Command injection

    Why it's wrong here

    OS command injection happens when user-supplied input is passed unsafely into a system shell command, allowing attackers to execute arbitrary operating system commands. Unlike XXE, this flaw is not tied to XML parsing or DTDs; it typically appears in functions like exec, system, or eval that interact with the command line. The symptom would be direct command execution output, not the file read or entity expansion caused by XXE, so this option is incorrect for the described issue.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.