PT0-002 Vulnerability Discovery and Analysis Practice Question
During a code review, a penetration tester identifies a PHP function that executes arbitrary shell commands. Which function poses the greatest security risk if user input is not sanitized?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
system
system() executes commands and returns output, allowing arbitrary command execution if input is unsanitized.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
echo
Why it's wrong here
In PHP, echo is a language construct, not a function, that prints one or more strings to the output. It performs no system calls and does not interpret the output as shell commands. Even if unsanitized user input is echoed, it manifests as reflected content (potentially enabling XSS) but cannot trigger direct OS command execution, so it is not a command execution sink in this context.
- ✗
strlen
Why it's wrong here
strlen() is a PHP built-in that calculates the byte length of a string and returns an integer. It performs no external process calls and has no visibility into the system shell; its return value is purely numeric. Although strlen may process attacker-controlled strings, it only reads the data to measure its size, making it incapable of executing commands or influencing OS-level operations.
- ✓
system
Why this is correct
system() is a PHP function that schedules an external command for execution by the system shell and displays its output. When user-controlled input is concatenated into the command string without proper escaping, an attacker can inject shell metacharacters such as ; or && to chain arbitrary commands (e.g., system('ping ' . $_GET['ip'])). This direct OS interaction makes system() a classic command injection sink and the correct dangerous function in the review.
- ✗
array_pop
Why it's wrong here
array_pop() is a PHP function that removes and returns the final element from an array, operating solely on in-memory data structures. It does not invoke the shell, execute external binaries, or parse string content as code. Even if the popped element contains malicious payloads, array_pop itself only retrieves the value; any execution would depend on a separate use of that value, so it is not a direct command execution vector.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.