Courseiva
mediumMultiple Choice

PT0-002 Practice Question: During a web application test, a penetration…

During a web application test, a penetration tester discovers that the server returns verbose error messages containing full file paths. Which type of attack is directly facilitated by this information disclosure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Path traversal

Verbose error messages revealing file paths can enable path traversal attacks, as the attacker learns the directory structure. SQL injection may be facilitated by database error messages, but file paths are specific to path traversal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Path traversal

    Why this is correct

    Disclosed internal file paths (e.g., from error messages, debug endpoints, or poorly commented source) give an attacker a map of the server's directory structure. Armed with this knowledge, they can craft traversal payloads such as ../../etc/passwd or use URL-encoded variants like %2e%2e%2f to bypass naive filters and read arbitrary files outside the web root. This is the core of a path traversal (directory traversal) vulnerability, where unchecked file path parameters directly expose host filesystem contents.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection occurs when user-supplied input is interpolated into SQL queries without proper parameterization, allowing an attacker to manipulate query logic or stack statements. Generic file path disclosures do not provide SQL syntax injection points, nor do they directly reveal database schemas or error messages that aid SQLi. While some SQL injection attacks leverage verbose database errors, those errors relate to query syntax, not filesystem paths, so path disclosure is a distinct weakness with no causal link to SQL injection.

  • ✗

    CSRF

    Why it's wrong here

    CSRF attacks force an authenticated user's browser to send forged state-changing requests (e.g., POST requests) to a vulnerable web application by relying on ambient authority like session cookies. A disclosed file path does not enable an attacker to craft such cross-site requests, nor does it bypass CSRF tokens, same-site cookies, or other CSRF defenses. The vulnerability class involves missing anti-CSRF tokens and predictable request patterns, not server-side path information leakage.

  • ✗

    Cross-site scripting

    Why it's wrong here

    Cross-site scripting requires an application to reflect or store attacker-controlled input that is later executed as client-side JavaScript in a victim's browser. Disclosing internal file paths is a server-side information disclosure that does not involve injecting scripts, encoding payloads into output contexts, or manipulating the DOM. Without input reflection or script insertion points, path leakage cannot be directly leveraged to execute XSS, making it an entirely distinct vulnerability type.

Go deeper

Related to this question

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.