Courseiva
easyMultiple Choice

PT0-002 Practice Question: During a penetration test, a tester discovers a…

During a penetration test, a tester discovers a web application that reflects user input in the HTTP response without sanitization. Which attack is most likely to be successful?

⚠ Common exam trap

A common mix-up: candidates confuse reflected XSS with stored XSS or CSRF, but the key differentiator is that the input is immediately reflected in the response without sanitization, not stored on the server or requiring a forged request.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reflected cross-site scripting

Reflected cross-site scripting (XSS) is the correct answer because the vulnerability described—user input reflected in the HTTP response without sanitization—directly enables an attacker to inject malicious scripts (e.g., JavaScript) that execute in the victim's browser. This occurs when the application fails to validate or encode the input before including it in the response, allowing the attacker to craft a URL with a script payload that, when visited, runs in the context of the vulnerable web application's origin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server-side request forgery

    Why it's wrong here

    Server-side request forgery (SSRF) is a vulnerability where an attacker manipulates the application to make server-side requests to arbitrary URLs, often to access internal resources or cloud metadata. It does not involve user input being echoed back in the HTTP response; instead, the server fetches resources on behalf of the attacker. The observation of reflected input in a web application is characteristic of a client-side injection flaw, not SSRF.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection (SQLi) arises when untrusted user input is concatenated directly into SQL queries, allowing an attacker to alter query logic or extract database contents. The mere reflection of input in a response does not demonstrate database interaction; SQLi typically requires evidence such as database error messages, UNION-based payloads, or time-based blind responses. Without such indicators, reflection is better explained by cross-site scripting, which occurs entirely in the client's browser.

  • ✓

    Reflected cross-site scripting

    Why this is correct

    Reflected cross-site scripting (XSS) occurs when an application immediately includes unvalidated or unencoded user input in its response, allowing an attacker to inject executable JavaScript. This matches the discovered behavior of input being echoed back; the payload runs in the victim's browser under the trust of the origin site. Exploitation usually involves tricking a victim into clicking a crafted URL, and the payload is non-persistent, disappearing after the response is rendered.

  • ✗

    Cross-site request forgery

    Why it's wrong here

    Cross-site request forgery (CSRF) attacks force an authenticated user's browser to send unwanted HTTP requests to a site where the user has an active session, exploiting cookies or other ambient authority. CSRF does not require the server to reflect input; instead, it relies on the browser automatically appending credentials to forged requests. Since the discovered issue involves reflection of user input in the response, CSRF is not a plausible explanation for this finding.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.