mediumMultiple Select
PT0-002 Practice Question: A web application test must cover OWASP Top 10
A web application test must cover OWASP Top 10. Which THREE should be explicitly included? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection testing
SQL injection testing (A) is explicitly required because injection flaws, including SQL injection, are a core OWASP Top 10 category (A03:2021 Injection) and must be tested by manipulating input fields and parameters to confirm the application safely handles untrusted data. Cross-site scripting (XSS) testing (C) is also explicitly required because XSS falls under the OWASP Top 10 injection category and involves verifying that user-supplied input is properly encoded or escaped in HTML, JavaScript, and attribute contexts. Broken authentication testing (E) is explicitly required because broken authentication is its own OWASP Top 10 category (A07:2021 Identification and Authentication Failures) and covers weak credential handling, session management flaws, and missing multi-factor authentication. Directory traversal testing (B) is not one of the OWASP Top 10 categories, although it may be tested as part of broader access control or misconfiguration checks. Buffer overflow testing (D) is not an OWASP Top 10 category either; it is primarily a memory-safety concern more relevant to native applications than typical web application testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SQL injection testing
Why this is correct
SQL injection maps to A03: Injection in the OWASP Top 10, so testing must attempt payloads through input fields, parameters and headers to confirm parameterised queries prevent database compromise. This directly satisfies the stem's OWASP Top 10 coverage requirement.
- ✗
Directory traversal testing
Why it's wrong here
Directory traversal maps to A01 Broken Access Control and A03 Injection in the current OWASP Top 10, so it is not a distinct listed category the stem asks to include explicitly. It tempts because it is a genuine web flaw, but the question targets the ten named categories themselves.
- ✓
Cross-site scripting (XSS) testing
Why this is correct
Cross-site scripting maps to A03: Injection, requiring reflected, stored and DOM-based payload testing to verify output encoding and Content Security Policy. Explicit XSS testing therefore satisfies the stem's mandate to cover OWASP Top 10 categories.
- ✗
Buffer overflow testing
Why it's wrong here
Buffer overflow is a memory-safety flaw, largely absent from the OWASP Top 10, which addresses categories like broken access control and injection. It tempts because it is a classic vulnerability, but it belongs to native code review and fuzzing, not the web application categories the stem requires.
- ✓
Broken authentication testing
Why this is correct
Broken authentication sits in the OWASP Top 10 as A07: Identification and Authentication Failures, so credential stuffing, session fixation and weak password recovery must be tested explicitly. This satisfies the stem's requirement to cover the OWASP Top 10 categories.
Go deeper
Related to this question
Learn chapter
Command Injection and Directory Traversal
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
Buffer overflow
A buffer overflow is a type of software vulnerability where a program writes more data to a memory buffer than it was designed to hold, causing adjacent memory to be overwritten.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.