Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

A tester is reviewing source code for security vulnerabilities. Which TWO of the following are examples of insecure coding practices that often lead to critical vulnerabilities?

⚠ Common exam trap

Many candidates confuse secure practices (like parameterized queries or allowlists) with insecure ones, or fail to recognize that storing plaintext credentials is a critical vulnerability because it exposes secrets if the configuration file is accessed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Concatenating user input directly into SQL queries

Option B is correct because concatenating user input directly into SQL queries builds the query string from untrusted data, allowing SQL injection (e.g., ' OR '1'='1) to alter query logic and potentially read, modify, or delete database contents. Option D is correct because storing plaintext credentials in configuration files exposes secrets to anyone with file or repository access, leading to credential theft, lateral movement, and full account compromise. Options A and C are secure practices: allowlist validation restricts input to known-good values, and parameterized queries separate code from data to prevent injection. Option E is also secure: prepared statements precompile the SQL structure so bound parameters cannot change query semantics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Validating input with allowlists

    Why it's wrong here

    Allowlist validation restricts input to a predefined set of safe values, effectively neutralizing injection attacks and malformed data. By rejecting anything outside the approved pattern, the application avoids relying on blocklists that can be bypassed with obfuscation. This is a foundational secure-coding practice and does not introduce a vulnerability.

  • ✓

    Concatenating user input directly into SQL queries

    Why this is correct

    Building SQL statements by directly concatenating unsanitized user input into query strings is the classic SQL injection flaw. An attacker can craft input that alters the query's structure, such as injecting a tautology or a stacked query, to bypass authentication, exfiltrate data, or execute arbitrary database commands. This violates the principle of separating code from data and is a critical vulnerability under OWASP Top 10 injection risks.

  • ✗

    Using parameterized queries for database operations

    Why it's wrong here

    Parameterized queries separate SQL logic from data by placing placeholders in the query and supplying values at execution time, so the database treats input as data only. This prevents malicious syntax from being interpreted as executable SQL, making the code inherently resistant to injection. Consequently, using parameterized queries is a secure database access pattern, not a vulnerability.

  • ✓

    Storing plaintext credentials in configuration files

    Why this is correct

    Storing plaintext credentials in configuration files exposes secrets to anyone who can read the file—whether through misconfigured repositories, backups, local code access, or path traversal. Unlike encrypted or environment-injected secrets, plaintext values require no decryption and can be used immediately to authenticate. Hardcoded secrets also hamper credential rotation and violate security best practices, making them a serious finding during code review.

  • ✗

    Using prepared statements in SQL

    Why it's wrong here

    Prepared statements compile the SQL query on the database server and then bind user-supplied values as parameters, ensuring those values are never parsed as SQL syntax. This server-side compilation provides a robust, DBMS-level defense against injection, and its presence in code reflects a secure implementation. However, a reviewer should still verify consistent use across the codebase, as any unwrapped query can reintroduce the vulnerability.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.