PT0-002 Vulnerability Discovery and Analysis Practice Question
During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
Direct concatenation of user input into SQL query without sanitization or parameterization is classic SQL injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
Cross-site scripting (XSS) fundamentally targets the client-side execution context, not the database. An attacker injects malicious JavaScript or HTML into the application's output, which is then rendered by a victim's browser. Unlike SQL injection, the injected payload does not alter any server-side SQL statement; instead, it manipulates how the page is interpreted client-side. Thus, the presence of unsanitized input alone does not indicate XSS unless it reaches an output sink such as echo or innerHTML.
- ✗
Path traversal
Why it's wrong here
Path traversal, also known as directory traversal, exploits a vulnerability in file path handling rather than database queries. An attacker injects sequences like ../ to escape the intended directory and read arbitrary files from the server's filesystem. This attack focuses on server-side file operations such as file_get_contents(), include, or fopen(), where user input is used to construct a filesystem path insecurely. Since the input is processed by the filesystem layer and not the SQL query parser, it cannot be classified as SQL injection.
- ✗
Command injection
Why it's wrong here
Command injection occurs when user-controlled input is passed unfiltered to an operating system command executed via functions like exec(), system(), or shell_exec(). The attacker appends shell metacharacters such as ;, |, or && to execute arbitrary commands on the host. This vulnerability exploits the shell's command parser, not the SQL query interpreter, so the injected content is processed by the operating system rather than a database. Therefore, it is a completely different attack class from SQL injection, which targets the SQL language syntax.
- ✓
SQL injection
Why this is correct
SQL injection is confirmed when user input is embedded directly into an SQL query without sanitization or parameterization, allowing the attacker to modify the query's logic. For example, input like ' OR '1'='1 can bypass authentication, and UNION SELECT statements can extract data from other tables. This occurs because the database engine interprets the attacker's input as part of the SQL syntax, not just as data. Proper defense involves prepared statements with bound parameters or stored procedures, which separate data from SQL code.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.