PT0-002 Attacks and Exploits Practice Question
During a web application test, the tester discovers a parameter that reflects user input in the response without proper encoding. The tester crafts a payload that executes JavaScript when another user views the page. Which type of XSS is this, and what is a primary risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reflected XSS; risk of session hijacking
Reflected XSS executes in the victim's browser when the malicious link is clicked, allowing session hijacking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stored XSS; risk of data theft from database
Why it's wrong here
Stored XSS requires the payload to be persisted by the server, such as in a database, and later delivered to other users when they load the stored content. In this test, however, the echoed parameter appears immediately in the same HTTP response, indicating a reflection from the request rather than storage. While stored XSS can indeed be exploited for database data theft, the immediate reflection scenario is the hallmark of reflected XSS.
- ✓
Reflected XSS; risk of session hijacking
Why this is correct
Reflected XSS occurs when user-supplied input is immediately echoed back in the server's response without proper sanitization or encoding. The attacker crafts a malicious URL containing script payload and lures the victim into clicking it; when the page loads, the script runs in the victim's session. This allows the attacker to steal session cookies via document.cookie and send them off-site, facilitating session hijacking. Because the payload is not persisted on the server, delivery depends on the victim accessing the crafted link.
- ✗
Blind XSS; risk of internal network scanning
Why it's wrong here
Blind XSS is a stored XSS variant where the payload is submitted and later executed in a different application context, such as an admin panel, not in the immediate response that the submitting user receives. In this scenario, the parameter is directly reflected in the same response, so the trigger is neither blind nor stored. The internal network scanning risk listed in the option is not the distinguishing characteristic; the key reason refutation is that the observed behavior is a direct reflection, not a delayed stored execution.
- ✗
DOM-based XSS; risk of client-side logic bypass
Why it's wrong here
DOM-based XSS is executed entirely within the client-side JavaScript: the vulnerable script reads attacker-controllable data, such as the URL fragment, and writes it into the DOM without validation. In this test, the parameter appears in the server-generated response, proving that the server itself is reflecting the unescaped value. Therefore, the root cause is server-side reflection, not a client-side sink, and the risk of client-side logic bypass is not the primary concern here.
Go deeper
Related to this question
Learn chapter
Burp Suite for Web Application Testing
Key term
Payload
In IT and cybersecurity, a payload is the core data or malicious code delivered within a packet, file, or attack that performs the actual intended action.
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.