mediumMultiple Choice
PT0-002 Practice Question: A tester runs a Python script to perform a…
Exhibit
Refer to the exhibit. ```python import requests url = 'http://example.com/download?file=../../etc/passwd' response = requests.get(url) print(response.status_code) ```
A tester runs a Python script to perform a directory traversal attack. The output shows: 'Error: 403 Forbidden'. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The web server is patched against traversal attacks
The web server is patched against traversal attacks. A 403 Forbidden response means the server understood the request but is explicitly refusing to authorize it, which is exactly what happens when a web server (or WAF) detects path traversal sequences like ../ and blocks them as a security policy. If the file simply did not exist, the server would typically return 404 Not Found rather than 403, and a malformed request would usually produce 400 Bad Request. Missing authentication would normally yield 401 Unauthorized (or a redirect to a login page), not 403, so option A does not fit either.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The script lacks authentication
Why it's wrong here
403 means the server understood the request but refused it; missing authentication usually yields 401 Unauthorized. The traversal payload was likely blocked by filtering. It is tempting because access denial sounds like an auth problem, but the status code distinguishes authorisation from authentication.
- ✗
The file does not exist
Why it's wrong here
A missing file returns 404 Not Found; 403 means the resource exists but access is denied, so path filtering or permissions blocked the traversal. It is tempting because traversal targets absent files, but the server's explicit refusal, not absence, produced this code.
- ✗
The request is malformed
Why it's wrong here
A malformed request typically returns 400 Bad Request, not 403; the server parsed the traversal path but refused it, indicating input filtering or a web application firewall. It is tempting because syntax errors do cause failures, but the specific status code points to authorisation or filtering.
- ✓
The web server is patched against traversal attacks
Why this is correct
A 403 Forbidden response indicates the server understood the request but refused it, typically because traversal sequences are filtered or the web server is patched against directory traversal. A missing file would return 404, and network failure would not yield an HTTP status.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.