easyMultiple Choice
PT0-002 Practice Question: During a penetration test, a tester discovers a…
During a penetration test, a tester discovers a web application that reflects user input in the HTTP response without sanitization. Which attack is most likely to be successful?
⚠ Common exam trap
A common mix-up: candidates confuse reflected XSS with stored XSS or CSRF, but the key differentiator is that the input is immediately reflected in the response without sanitization, not stored on the server or requiring a forged request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reflected cross-site scripting
Reflected cross-site scripting (XSS) is the correct answer because the vulnerability described—user input reflected in the HTTP response without sanitization—directly enables an attacker to inject malicious scripts (e.g., JavaScript) that execute in the victim's browser. This occurs when the application fails to validate or encode the input before including it in the response, allowing the attacker to craft a URL with a script payload that, when visited, runs in the context of the vulnerable web application's origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-side request forgery
Why it's wrong here
Server-side request forgery (SSRF) is a vulnerability where an attacker manipulates the application to make server-side requests to arbitrary URLs, often to access internal resources or cloud metadata. It does not involve user input being echoed back in the HTTP response; instead, the server fetches resources on behalf of the attacker. The observation of reflected input in a web application is characteristic of a client-side injection flaw, not SSRF.
- ✗
SQL injection
Why it's wrong here
SQL injection (SQLi) arises when untrusted user input is concatenated directly into SQL queries, allowing an attacker to alter query logic or extract database contents. The mere reflection of input in a response does not demonstrate database interaction; SQLi typically requires evidence such as database error messages, UNION-based payloads, or time-based blind responses. Without such indicators, reflection is better explained by cross-site scripting, which occurs entirely in the client's browser.
- ✓
Reflected cross-site scripting
Why this is correct
Reflected cross-site scripting (XSS) occurs when an application immediately includes unvalidated or unencoded user input in its response, allowing an attacker to inject executable JavaScript. This matches the discovered behavior of input being echoed back; the payload runs in the victim's browser under the trust of the origin site. Exploitation usually involves tricking a victim into clicking a crafted URL, and the payload is non-persistent, disappearing after the response is rendered.
- ✗
Cross-site request forgery
Why it's wrong here
Cross-site request forgery (CSRF) attacks force an authenticated user's browser to send unwanted HTTP requests to a site where the user has an active session, exploiting cookies or other ambient authority. CSRF does not require the server to reflect input; instead, it relies on the browser automatically appending credentials to forged requests. Since the discovered issue involves reflection of user input in the response, CSRF is not a plausible explanation for this finding.
Go deeper
Related to this question
Learn chapter
Advanced Nmap: Scripting Engine (NSE)
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
Payload
In IT and cybersecurity, a payload is the core data or malicious code delivered within a packet, file, or attack that performs the actual intended action.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.