Courseiva

PT0-002 Vulnerability Discovery and Analysis Practice Question

During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

Direct concatenation of user input into SQL query without sanitization or parameterization is classic SQL injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting (XSS) fundamentally targets the client-side execution context, not the database. An attacker injects malicious JavaScript or HTML into the application's output, which is then rendered by a victim's browser. Unlike SQL injection, the injected payload does not alter any server-side SQL statement; instead, it manipulates how the page is interpreted client-side. Thus, the presence of unsanitized input alone does not indicate XSS unless it reaches an output sink such as echo or innerHTML.

  • ✗

    Path traversal

    Why it's wrong here

    Path traversal, also known as directory traversal, exploits a vulnerability in file path handling rather than database queries. An attacker injects sequences like ../ to escape the intended directory and read arbitrary files from the server's filesystem. This attack focuses on server-side file operations such as file_get_contents(), include, or fopen(), where user input is used to construct a filesystem path insecurely. Since the input is processed by the filesystem layer and not the SQL query parser, it cannot be classified as SQL injection.

  • ✗

    Command injection

    Why it's wrong here

    Command injection occurs when user-controlled input is passed unfiltered to an operating system command executed via functions like exec(), system(), or shell_exec(). The attacker appends shell metacharacters such as ;, |, or && to execute arbitrary commands on the host. This vulnerability exploits the shell's command parser, not the SQL query interpreter, so the injected content is processed by the operating system rather than a database. Therefore, it is a completely different attack class from SQL injection, which targets the SQL language syntax.

  • ✓

    SQL injection

    Why this is correct

    SQL injection is confirmed when user input is embedded directly into an SQL query without sanitization or parameterization, allowing the attacker to modify the query's logic. For example, input like ' OR '1'='1 can bypass authentication, and UNION SELECT statements can extract data from other tables. This occurs because the database engine interprets the attacker's input as part of the SQL syntax, not just as data. Proper defense involves prepared statements with bound parameters or stored procedures, which separate data from SQL code.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.