PT0-002 Attacks and Exploits Practice Question
During a web application test, you discover an endpoint that accepts a URL parameter and fetches the content. You try `http://169.254.169.254/latest/meta-data/` and receive a response. Which vulnerability is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server-Side Request Forgery (SSRF)
The IP 169.254.169.254 is the cloud metadata endpoint; accessing it indicates SSRF.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-Site Request Forgery (CSRF)
Why it's wrong here
Cross-Site Request Forgery (CSRF) exploits the trust a web application has in an authenticated user's browser, forcing the victim's session to perform unintended actions. It does not make the server itself initiate outbound HTTP requests, so an attacker cannot use it to have the vulnerable server fetch internal or cloud metadata URLs. The attack vector is entirely client-side, with responses not returned to the attacker, which is incompatible with the described server-side endpoint behavior.
- ✗
Local File Inclusion (LFI)
Why it's wrong here
Local File Inclusion (LFI) leverages insecure file inclusion mechanisms to read files from the server's local filesystem, such as /etc/passwd or application source code. Cloud metadata services, like AWS IMDS at 169.254.169.254, are exposed via HTTP over a link-local network, not as filesystem paths that PHP's include or file_get_contents would access. While LFI can expose sensitive data, it cannot directly retrieve HTTP-based cloud metadata, making it the wrong diagnosis for a server-side fetch endpoint.
- ✓
Server-Side Request Forgery (SSRF)
Why this is correct
Server-Side Request Forgery (SSRF) occurs when a web application fetches a user-supplied URL server-side without adequate validation, allowing the attacker to target internal hosts or cloud metadata services. In this scenario, the discovered endpoint likely accepts a URL and makes an HTTP request on behalf of the server, enabling the attacker to query 169.254.169.254/latest/meta-data/ and exfiltrate instance credentials. This matches the described behavior exactly: the server, not the user's browser, performs the request and returns the response to the attacker.
- ✗
XML External Entity (XXE)
Why it's wrong here
XML External Entity (XXE) vulnerabilities arise from insecure parsing of XML documents, permitting malicious external entities to read local files or issue limited HTTP requests via the entity's system identifier. Although advanced XXE payloads can sometimes trigger SSRF-like behavior, the primary and most direct impact in typical real-world cases is file disclosure through the XML parser, not a dedicated server-side URL fetch mechanism. Since the discovered endpoint likely performs arbitrary URL fetches independent of XML processing, SSRF is a better fit than XXE.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.