Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a web application test, the tester discovers a parameter that reflects user input in the response without proper encoding. The tester crafts a payload that executes JavaScript when another user views the page. Which type of XSS is this, and what is a primary risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reflected XSS; risk of session hijacking

Reflected XSS executes in the victim's browser when the malicious link is clicked, allowing session hijacking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stored XSS; risk of data theft from database

    Why it's wrong here

    Stored XSS requires the payload to be persisted by the server, such as in a database, and later delivered to other users when they load the stored content. In this test, however, the echoed parameter appears immediately in the same HTTP response, indicating a reflection from the request rather than storage. While stored XSS can indeed be exploited for database data theft, the immediate reflection scenario is the hallmark of reflected XSS.

  • ✓

    Reflected XSS; risk of session hijacking

    Why this is correct

    Reflected XSS occurs when user-supplied input is immediately echoed back in the server's response without proper sanitization or encoding. The attacker crafts a malicious URL containing script payload and lures the victim into clicking it; when the page loads, the script runs in the victim's session. This allows the attacker to steal session cookies via document.cookie and send them off-site, facilitating session hijacking. Because the payload is not persisted on the server, delivery depends on the victim accessing the crafted link.

  • ✗

    Blind XSS; risk of internal network scanning

    Why it's wrong here

    Blind XSS is a stored XSS variant where the payload is submitted and later executed in a different application context, such as an admin panel, not in the immediate response that the submitting user receives. In this scenario, the parameter is directly reflected in the same response, so the trigger is neither blind nor stored. The internal network scanning risk listed in the option is not the distinguishing characteristic; the key reason refutation is that the observed behavior is a direct reflection, not a delayed stored execution.

  • ✗

    DOM-based XSS; risk of client-side logic bypass

    Why it's wrong here

    DOM-based XSS is executed entirely within the client-side JavaScript: the vulnerable script reads attacker-controllable data, such as the URL fragment, and writes it into the DOM without validation. In this test, the parameter appears in the server-generated response, proving that the server itself is reflecting the unescaped value. Therefore, the root cause is server-side reflection, not a client-side sink, and the risk of client-side logic bypass is not the primary concern here.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.