PT0-002 Attacks and Exploits Practice Question
You are attacking a web application and notice that it makes requests to internal services. You attempt to access the cloud metadata endpoint at http://169.254.169.254/. Which vulnerability are you most likely exploiting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSRF (Server-Side Request Forgery)
SSRF (Server-Side Request Forgery) allows an attacker to make requests from the server to internal resources, including cloud metadata endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SSRF (Server-Side Request Forgery)
Why this is correct
SSRF is the correct answer because the web application is being manipulated into making server-side HTTP requests to a URL controlled by the attacker. In cloud environments, the metadata endpoint (e.g., http://169.254.169.254/latest/meta-data/) is reachable only from the host, so a successful SSRF lets the attacker read instance credentials or security tokens. This directly matches the scenario of the server fetching an internal resource, unlike the other options.
- ✗
XXE (XML External Entity)
Why it's wrong here
XXE is incorrect because it requires the application to parse an XML document, and the attacker must be able to inject an external entity into that XML. While XXE can sometimes read files or make internal HTTP requests via parameter entities, the described behavior—where the server blindly fetches a URL—is not inherently XML-based. The metadata endpoint is most commonly reached through SSRF, not through XML parsing, and there is no indication that XML input is present.
- ✗
Command injection
Why it's wrong here
Command injection is incorrect because it involves injecting OS-level commands (e.g., `cat /etc/passwd` or `curl`) into a shell executed by the server, typically due to unsanitized input passed to a system call. The scenario here does not mention command execution; it describes the server making HTTP requests, which is a function of the application's URL-fetching logic, not an OS shell. While an attacker could potentially use command injection to run `curl` to access the metadata endpoint, that would be a separate and more complex attack chain, not the direct vulnerability described.
- ✗
CSRF (Cross-Site Request Forgery)
Why it's wrong here
CSRF is incorrect because it exploits the trust a web application has in a user's browser by making the browser send authenticated requests to the application. It does not cause the server to make arbitrary outbound requests to internal resources like the metadata endpoint. The metadata service is accessible only from the server's local network, so a user's browser cannot reach it, and CSRF would not be able to target it. This makes SSRF the only option that properly describes the server being tricked into making requests, rather than the browser.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.