Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

During a code review, a penetration tester identifies a PHP function that executes arbitrary shell commands. Which function poses the greatest security risk if user input is not sanitized?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

system

system() executes commands and returns output, allowing arbitrary command execution if input is unsanitized.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    echo

    Why it's wrong here

    In PHP, echo is a language construct, not a function, that prints one or more strings to the output. It performs no system calls and does not interpret the output as shell commands. Even if unsanitized user input is echoed, it manifests as reflected content (potentially enabling XSS) but cannot trigger direct OS command execution, so it is not a command execution sink in this context.

  • ✗

    strlen

    Why it's wrong here

    strlen() is a PHP built-in that calculates the byte length of a string and returns an integer. It performs no external process calls and has no visibility into the system shell; its return value is purely numeric. Although strlen may process attacker-controlled strings, it only reads the data to measure its size, making it incapable of executing commands or influencing OS-level operations.

  • ✓

    system

    Why this is correct

    system() is a PHP function that schedules an external command for execution by the system shell and displays its output. When user-controlled input is concatenated into the command string without proper escaping, an attacker can inject shell metacharacters such as ; or && to chain arbitrary commands (e.g., system('ping ' . $_GET['ip'])). This direct OS interaction makes system() a classic command injection sink and the correct dangerous function in the review.

  • ✗

    array_pop

    Why it's wrong here

    array_pop() is a PHP function that removes and returns the final element from an array, operating solely on in-memory data structures. It does not invoke the shell, execute external binaries, or parse string content as code. Even if the popped element contains malicious payloads, array_pop itself only retrieves the value; any execution would depend on a separate use of that value, so it is not a direct command execution vector.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.