Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a web application test, you discover a parameter that reflects user input in the response without proper encoding. You craft a payload that executes JavaScript in the victim's browser. This vulnerability is best classified as:

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reflected XSS

Reflected XSS occurs when user input is immediately reflected back in the response without proper sanitization, allowing script execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stored XSS

    Why it's wrong here

    Stored XSS is characterized by the payload being permanently stored on the server, such as in a database or file, and then served to every user who accesses that page. In this test, the parameter is reflected back immediately in the response rather than being saved, so the attack does not persist and would only affect the single user who supplies the crafted input, making it a reflected, not stored, vulnerability.

  • ✗

    Server-side request forgery (SSRF)

    Why it's wrong here

    Server-side request forgery (SSRF) is an attack where the attacker controls a URL that the server fetches, allowing the server to make requests to internal resources, cloud metadata, or other systems. It is a server-side logic flaw, not a client-side script injection, and it does not involve the server echoing the attacker's input into a response body that executes in a browser. Therefore, observing a parameter reflected in the HTTP response is not indicative of SSRF.

  • ✓

    Reflected XSS

    Why this is correct

    Reflected XSS occurs when a user-controlled parameter is embedded into the HTTP response without proper encoding or sanitization, and the browser executes the injected script as part of the page. The script is triggered only when the victim clicks a crafted link, making the attack non-persistent. Since the parameter is directly reflected in the response and the server is echoing the input, this matches the classic signature of reflected XSS.

  • ✗

    DOM-based XSS

    Why it's wrong here

    DOM-based XSS arises when client-side JavaScript reads attacker-controlled data (e.g., from location.hash or document.referrer) and writes it to a dangerous sink like innerHTML, never involving the server in the reflection. The question indicates the parameter is reflected in the server's response, which points to a server-side reflection rather than a purely client-side DOM manipulation. Thus, the vulnerability is not DOM-based because the server itself is including the unencoded input in the output.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.