easyMultiple Choice
PT0-002 Practice Question: A tester is reviewing code and sees a function…
A tester is reviewing code and sees a function that concatenates user input directly into a SQL query. Which vulnerability is most likely present?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
SQL injection, because concatenating untrusted user input directly into a SQL query allows an attacker to alter the query's structure and execute arbitrary SQL statements. This is the classic pattern for SQL injection, where input such as ' OR '1'='1 or UNION SELECT can bypass authentication or extract data. Buffer overflow (A) involves writing beyond allocated memory bounds and is not indicated by string concatenation into a query. Command injection (C) occurs when input is passed to an OS shell or command interpreter, not a SQL query. Cross-site scripting (D) involves injecting script into web pages rendered to other users, which is a different context from SQL query construction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Buffer overflow
Why it's wrong here
Buffer overflow exploits a program writing beyond the bounds of a fixed-length buffer to corrupt adjacent memory, typically through unsafe functions like strcpy(), strcat(), or gets(). In this scenario, the flaw is in how user input is concatenated into a SQL string, not into a memory buffer; the concatenation itself does not overrun memory, so buffer overflow is not the vulnerability.
- ✓
SQL injection
Why this is correct
SQL injection occurs when untrusted input is concatenated directly into a SQL statement without proper parameterization or escaping, allowing an attacker to alter the query's logic. For example, injecting ' OR '1'='1 modifies a WHERE clause to bypass authentication or retrieve all rows. Since the code review shows concatenation into a database query, this is the correct vulnerability: the attacker can manipulate the SQL command structure.
- ✗
Command injection
Why it's wrong here
Command injection targets system command execution functions such as system(), exec(), or shell_exec(), where user input is concatenated into a command line for the operating system. Although it also stems from unsafe concatenation, the code under review involves SQL, not OS command invocation, so applying command injection would misidentify the vulnerable sink and the execution context.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
Cross-site scripting (XSS) is a client-side vulnerability that injects malicious scripts into web pages viewed by other users, often via unsafe concatenation of input into HTML or JavaScript. In contrast, the given code concatenates input into a SQL statement executed on the server; XSS would require the input to reach a browser-rendered context, making it irrelevant to this database-focused issue.
Go deeper
Related to this question
Learn chapter
Advanced Nmap: Scripting Engine (NSE)
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
Key term
Command injection
Command injection is a security vulnerability where an attacker inserts malicious commands into a system through an input field, tricking the application into executing them on the underlying operating system.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.