PT0-002 Attacks and Exploits Practice Question
During a web application test, you discover a parameter that reflects user input in the response without proper encoding. You craft a payload that executes JavaScript in the victim's browser. This vulnerability is best classified as:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reflected XSS
Reflected XSS occurs when user input is immediately reflected back in the response without proper sanitization, allowing script execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stored XSS
Why it's wrong here
Stored XSS is characterized by the payload being permanently stored on the server, such as in a database or file, and then served to every user who accesses that page. In this test, the parameter is reflected back immediately in the response rather than being saved, so the attack does not persist and would only affect the single user who supplies the crafted input, making it a reflected, not stored, vulnerability.
- ✗
Server-side request forgery (SSRF)
Why it's wrong here
Server-side request forgery (SSRF) is an attack where the attacker controls a URL that the server fetches, allowing the server to make requests to internal resources, cloud metadata, or other systems. It is a server-side logic flaw, not a client-side script injection, and it does not involve the server echoing the attacker's input into a response body that executes in a browser. Therefore, observing a parameter reflected in the HTTP response is not indicative of SSRF.
- ✓
Reflected XSS
Why this is correct
Reflected XSS occurs when a user-controlled parameter is embedded into the HTTP response without proper encoding or sanitization, and the browser executes the injected script as part of the page. The script is triggered only when the victim clicks a crafted link, making the attack non-persistent. Since the parameter is directly reflected in the response and the server is echoing the input, this matches the classic signature of reflected XSS.
- ✗
DOM-based XSS
Why it's wrong here
DOM-based XSS arises when client-side JavaScript reads attacker-controlled data (e.g., from location.hash or document.referrer) and writes it to a dangerous sink like innerHTML, never involving the server in the reflection. The question indicates the parameter is reflected in the server's response, which points to a server-side reflection rather than a purely client-side DOM manipulation. Thus, the vulnerability is not DOM-based because the server itself is including the unencoded input in the output.
Go deeper
Related to this question
Learn chapter
Burp Suite for Web Application Testing
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
Payload
In IT and cybersecurity, a payload is the core data or malicious code delivered within a packet, file, or attack that performs the actual intended action.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.