Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

You are attacking a web application and notice that it makes requests to internal services. You attempt to access the cloud metadata endpoint at http://169.254.169.254/. Which vulnerability are you most likely exploiting?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSRF (Server-Side Request Forgery)

SSRF (Server-Side Request Forgery) allows an attacker to make requests from the server to internal resources, including cloud metadata endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SSRF (Server-Side Request Forgery)

    Why this is correct

    SSRF is the correct answer because the web application is being manipulated into making server-side HTTP requests to a URL controlled by the attacker. In cloud environments, the metadata endpoint (e.g., http://169.254.169.254/latest/meta-data/) is reachable only from the host, so a successful SSRF lets the attacker read instance credentials or security tokens. This directly matches the scenario of the server fetching an internal resource, unlike the other options.

  • ✗

    XXE (XML External Entity)

    Why it's wrong here

    XXE is incorrect because it requires the application to parse an XML document, and the attacker must be able to inject an external entity into that XML. While XXE can sometimes read files or make internal HTTP requests via parameter entities, the described behavior—where the server blindly fetches a URL—is not inherently XML-based. The metadata endpoint is most commonly reached through SSRF, not through XML parsing, and there is no indication that XML input is present.

  • ✗

    Command injection

    Why it's wrong here

    Command injection is incorrect because it involves injecting OS-level commands (e.g., `cat /etc/passwd` or `curl`) into a shell executed by the server, typically due to unsanitized input passed to a system call. The scenario here does not mention command execution; it describes the server making HTTP requests, which is a function of the application's URL-fetching logic, not an OS shell. While an attacker could potentially use command injection to run `curl` to access the metadata endpoint, that would be a separate and more complex attack chain, not the direct vulnerability described.

  • ✗

    CSRF (Cross-Site Request Forgery)

    Why it's wrong here

    CSRF is incorrect because it exploits the trust a web application has in a user's browser by making the browser send authenticated requests to the application. It does not cause the server to make arbitrary outbound requests to internal resources like the metadata endpoint. The metadata service is accessible only from the server's local network, so a user's browser cannot reach it, and CSRF would not be able to target it. This makes SSRF the only option that properly describes the server being tricked into making requests, rather than the browser.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.