Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

During a web application penetration test, a tester wants to identify vulnerabilities that allow unauthorized access to internal resources. Which TWO of the following are commonly exploited to access internal services?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-side request forgery (SSRF)

SSRF can be used to access internal services by making the server request internal IPs. XXE can also be used for SSRF by using external entities to make HTTP requests. XSS is client-side, SQLi is database, command injection is OS commands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Server-side request forgery (SSRF)

    Why this is correct

    SSRF is the correct answer because it directly exploits the server's ability to fetch URLs. An attacker can manipulate server-side requests to target internal addresses (127.0.0.1, 10.0.0.0/8) or cloud metadata endpoints, thus accessing resources that are not exposed to the internet. This makes SSRF the primary technique for reaching internal services from a vulnerable web application.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    XSS is incorrect because the injected script executes in the context of the victim's browser, not on the web server. While XSS can steal cookies or perform client-side actions, it cannot make the server itself send requests to internal hosts, so it fails to achieve access to internal network resources.

  • ✗

    SQL injection (SQLi)

    Why it's wrong here

    SQL injection is not the correct technique for accessing internal services because it only manipulates database queries. It can exfiltrate sensitive data or bypass authentication, but it does not provide the ability to issue arbitrary HTTP or TCP requests to internal infrastructure, which is the core functionality of SSRF.

  • ✗

    Command injection

    Why it's wrong here

    Command injection is incorrect in this context because it focuses on executing operating system commands on the server, rather than controlling the application's outgoing network requests. Although an attacker might leverage command injection to run tools like curl, the vulnerability class itself is distinct; SSRF specifically abuses the application's own HTTP request features, making it the more precise and expected answer for probing internal resources.

  • ✓

    XML external entity (XXE) injection

    Why this is correct

    XXE injection is also correct because, when an XML parser processes external entities, it can be forced to fetch internal URLs or file contents. This effectively performs SSRF without requiring a dedicated URL parameter, as the server-side XML parsing acts as the request origin, enabling access to internal services that are otherwise protected.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.