PT0-002 Attacks and Exploits Practice Question
During a web application penetration test, a tester wants to identify vulnerabilities that allow unauthorized access to internal resources. Which TWO of the following are commonly exploited to access internal services?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server-side request forgery (SSRF)
SSRF can be used to access internal services by making the server request internal IPs. XXE can also be used for SSRF by using external entities to make HTTP requests. XSS is client-side, SQLi is database, command injection is OS commands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Server-side request forgery (SSRF)
Why this is correct
SSRF is the correct answer because it directly exploits the server's ability to fetch URLs. An attacker can manipulate server-side requests to target internal addresses (127.0.0.1, 10.0.0.0/8) or cloud metadata endpoints, thus accessing resources that are not exposed to the internet. This makes SSRF the primary technique for reaching internal services from a vulnerable web application.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
XSS is incorrect because the injected script executes in the context of the victim's browser, not on the web server. While XSS can steal cookies or perform client-side actions, it cannot make the server itself send requests to internal hosts, so it fails to achieve access to internal network resources.
- ✗
SQL injection (SQLi)
Why it's wrong here
SQL injection is not the correct technique for accessing internal services because it only manipulates database queries. It can exfiltrate sensitive data or bypass authentication, but it does not provide the ability to issue arbitrary HTTP or TCP requests to internal infrastructure, which is the core functionality of SSRF.
- ✗
Command injection
Why it's wrong here
Command injection is incorrect in this context because it focuses on executing operating system commands on the server, rather than controlling the application's outgoing network requests. Although an attacker might leverage command injection to run tools like curl, the vulnerability class itself is distinct; SSRF specifically abuses the application's own HTTP request features, making it the more precise and expected answer for probing internal resources.
- ✓
XML external entity (XXE) injection
Why this is correct
XXE injection is also correct because, when an XML parser processes external entities, it can be forced to fetch internal URLs or file contents. This effectively performs SSRF without requiring a dedicated URL parameter, as the server-side XML parsing acts as the request origin, enabling access to internal services that are otherwise protected.
Go deeper
Related to this question
Learn chapter
IDOR and Broken Access Control
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
Command injection
Command injection is a security vulnerability where an attacker inserts malicious commands into a system through an input field, tricking the application into executing them on the underlying operating system.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.