PT0-002 Vulnerability Discovery and Analysis Practice Question
A tester is reviewing source code for security vulnerabilities. Which TWO of the following are examples of insecure coding practices that often lead to critical vulnerabilities?
⚠ Common exam trap
Many candidates confuse secure practices (like parameterized queries or allowlists) with insecure ones, or fail to recognize that storing plaintext credentials is a critical vulnerability because it exposes secrets if the configuration file is accessed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Concatenating user input directly into SQL queries
Option B is correct because concatenating user input directly into SQL queries builds the query string from untrusted data, allowing SQL injection (e.g., ' OR '1'='1) to alter query logic and potentially read, modify, or delete database contents. Option D is correct because storing plaintext credentials in configuration files exposes secrets to anyone with file or repository access, leading to credential theft, lateral movement, and full account compromise. Options A and C are secure practices: allowlist validation restricts input to known-good values, and parameterized queries separate code from data to prevent injection. Option E is also secure: prepared statements precompile the SQL structure so bound parameters cannot change query semantics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Validating input with allowlists
Why it's wrong here
Allowlist validation restricts input to a predefined set of safe values, effectively neutralizing injection attacks and malformed data. By rejecting anything outside the approved pattern, the application avoids relying on blocklists that can be bypassed with obfuscation. This is a foundational secure-coding practice and does not introduce a vulnerability.
- ✓
Concatenating user input directly into SQL queries
Why this is correct
Building SQL statements by directly concatenating unsanitized user input into query strings is the classic SQL injection flaw. An attacker can craft input that alters the query's structure, such as injecting a tautology or a stacked query, to bypass authentication, exfiltrate data, or execute arbitrary database commands. This violates the principle of separating code from data and is a critical vulnerability under OWASP Top 10 injection risks.
- ✗
Using parameterized queries for database operations
Why it's wrong here
Parameterized queries separate SQL logic from data by placing placeholders in the query and supplying values at execution time, so the database treats input as data only. This prevents malicious syntax from being interpreted as executable SQL, making the code inherently resistant to injection. Consequently, using parameterized queries is a secure database access pattern, not a vulnerability.
- ✓
Storing plaintext credentials in configuration files
Why this is correct
Storing plaintext credentials in configuration files exposes secrets to anyone who can read the file—whether through misconfigured repositories, backups, local code access, or path traversal. Unlike encrypted or environment-injected secrets, plaintext values require no decryption and can be used immediately to authenticate. Hardcoded secrets also hamper credential rotation and violate security best practices, making them a serious finding during code review.
- ✗
Using prepared statements in SQL
Why it's wrong here
Prepared statements compile the SQL query on the database server and then bind user-supplied values as parameters, ensuring those values are never parsed as SQL syntax. This server-side compilation provides a robust, DBMS-level defense against injection, and its presence in code reflects a secure implementation. However, a reviewer should still verify consistent use across the codebase, as any unwrapped query can reintroduce the vulnerability.
Go deeper
Related to this question
Learn chapter
Post-Exploitation File Transfer Techniques
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.