mediumMultiple Choice
PT0-002 Practice Question: During a web application test, a penetration…
During a web application test, a penetration tester discovers that the server returns verbose error messages containing full file paths. Which type of attack is directly facilitated by this information disclosure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Path traversal
Verbose error messages revealing file paths can enable path traversal attacks, as the attacker learns the directory structure. SQL injection may be facilitated by database error messages, but file paths are specific to path traversal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Path traversal
Why this is correct
Disclosed internal file paths (e.g., from error messages, debug endpoints, or poorly commented source) give an attacker a map of the server's directory structure. Armed with this knowledge, they can craft traversal payloads such as ../../etc/passwd or use URL-encoded variants like %2e%2e%2f to bypass naive filters and read arbitrary files outside the web root. This is the core of a path traversal (directory traversal) vulnerability, where unchecked file path parameters directly expose host filesystem contents.
- ✗
SQL injection
Why it's wrong here
SQL injection occurs when user-supplied input is interpolated into SQL queries without proper parameterization, allowing an attacker to manipulate query logic or stack statements. Generic file path disclosures do not provide SQL syntax injection points, nor do they directly reveal database schemas or error messages that aid SQLi. While some SQL injection attacks leverage verbose database errors, those errors relate to query syntax, not filesystem paths, so path disclosure is a distinct weakness with no causal link to SQL injection.
- ✗
CSRF
Why it's wrong here
CSRF attacks force an authenticated user's browser to send forged state-changing requests (e.g., POST requests) to a vulnerable web application by relying on ambient authority like session cookies. A disclosed file path does not enable an attacker to craft such cross-site requests, nor does it bypass CSRF tokens, same-site cookies, or other CSRF defenses. The vulnerability class involves missing anti-CSRF tokens and predictable request patterns, not server-side path information leakage.
- ✗
Cross-site scripting
Why it's wrong here
Cross-site scripting requires an application to reflect or store attacker-controlled input that is later executed as client-side JavaScript in a victim's browser. Disclosing internal file paths is a server-side information disclosure that does not involve injecting scripts, encoding payloads into output contexts, or manipulating the DOM. Without input reflection or script insertion points, path leakage cannot be directly leveraged to execute XSS, making it an entirely distinct vulnerability type.
Go deeper
Related to this question
Learn chapter
Pass-the-Hash and Pass-the-Ticket Attacks
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
Key term
Path traversal
Path traversal is a web security vulnerability that allows an attacker to access files and directories stored outside the web server's root folder by manipulating file paths in user-supplied input.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.