PT0-002 Attacks and Exploits Practice Question
During a web application test, a tester discovers an endpoint that fetches a URL from user input without validation. They attempt to access the AWS metadata endpoint. Which IP address is commonly used for the cloud metadata service?
⚠ Common exam trap
The trap is confusing the metadata IP with common private or loopback addresses — candidates who have not memorized 169.254.169.254 may pick 127.0.0.1 thinking 'local service,' but the metadata service is a distinct link-local endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
169.254.169.254
169.254.169.254 is the link-local IPv4 address used by AWS EC2 Instance Metadata Service (IMDS), and it is also used by Azure, GCP, and OpenStack for their metadata services. An SSRF vulnerability that can reach this address can retrieve IAM credentials from the instance role, making it a critical finding in cloud-hosted web app tests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
169.254.169.254
Why this is correct
169.254.169.254 is the link-local address used by AWS, Azure and GCP instance metadata services. Reaching it via an unvalidated URL-fetch parameter demonstrates server-side request forgery, letting the tester retrieve IAM credentials and instance configuration from the cloud metadata endpoint.
- ✗
10.0.0.1
Why it's wrong here
10.0.0.1 is a private RFC 1918 address used for internal LAN gateways, not the link-local metadata service. It is tempting because SSRF payloads often target private ranges to reach internal hosts, and 10.0.0.1 is a common router address, but AWS metadata sits at a fixed link-local IP.
- ✗
127.0.0.1
Why it's wrong here
Loopback 127.0.0.1 addresses the local host only, so a server-side request forgery aimed at the instance metadata service never leaves the machine. It is tempting because loopback is the classic SSRF target for reaching internal admin interfaces bound to localhost, which is a different objective from querying the cloud metadata endpoint.
- ✗
192.168.1.1
Why it's wrong here
192.168.1.1 is a typical private LAN gateway address, not the cloud metadata service. The AWS instance metadata endpoint is 169.254.169.254, a link-local address reachable from the instance. Testers target it for SSRF credential theft; 192.168.1.1 serves no metadata role.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.