Courseiva
easyMultiple Choice

PT0-002 Practice Question: A tester is reviewing code and sees a function…

A tester is reviewing code and sees a function that concatenates user input directly into a SQL query. Which vulnerability is most likely present?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

SQL injection, because concatenating untrusted user input directly into a SQL query allows an attacker to alter the query's structure and execute arbitrary SQL statements. This is the classic pattern for SQL injection, where input such as ' OR '1'='1 or UNION SELECT can bypass authentication or extract data. Buffer overflow (A) involves writing beyond allocated memory bounds and is not indicated by string concatenation into a query. Command injection (C) occurs when input is passed to an OS shell or command interpreter, not a SQL query. Cross-site scripting (D) involves injecting script into web pages rendered to other users, which is a different context from SQL query construction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Buffer overflow

    Why it's wrong here

    Buffer overflow exploits a program writing beyond the bounds of a fixed-length buffer to corrupt adjacent memory, typically through unsafe functions like strcpy(), strcat(), or gets(). In this scenario, the flaw is in how user input is concatenated into a SQL string, not into a memory buffer; the concatenation itself does not overrun memory, so buffer overflow is not the vulnerability.

  • ✓

    SQL injection

    Why this is correct

    SQL injection occurs when untrusted input is concatenated directly into a SQL statement without proper parameterization or escaping, allowing an attacker to alter the query's logic. For example, injecting ' OR '1'='1 modifies a WHERE clause to bypass authentication or retrieve all rows. Since the code review shows concatenation into a database query, this is the correct vulnerability: the attacker can manipulate the SQL command structure.

  • ✗

    Command injection

    Why it's wrong here

    Command injection targets system command execution functions such as system(), exec(), or shell_exec(), where user input is concatenated into a command line for the operating system. Although it also stems from unsafe concatenation, the code under review involves SQL, not OS command invocation, so applying command injection would misidentify the vulnerable sink and the execution context.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting (XSS) is a client-side vulnerability that injects malicious scripts into web pages viewed by other users, often via unsafe concatenation of input into HTML or JavaScript. In contrast, the given code concatenates input into a SQL statement executed on the server; XSS would require the input to reach a browser-rendered context, making it irrelevant to this database-focused issue.

Go deeper

Related to this question

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.