Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

What Is Stored (Persistent) XSS?

A web form stores a user's comment and later displays it to other users. A tester submits <script>alert(1)</script> and the script runs in the browser. What vulnerability is this?

Quick Answer

The answer is stored (persistent) cross-site scripting (XSS). This is correct because the malicious script, `<script>alert(1)</script>`, is submitted through a web form, stored on the server, and then executed in the browsers of other users who view the comment—this persistence on the server side is what distinguishes stored XSS from reflected or DOM-based variants. On the Security+ SY0-701 exam, this scenario tests your understanding of input validation and output encoding failures; a common trap is confusing stored XSS with reflected XSS, but remember that stored XSS involves data that is permanently saved and served to multiple users, while reflected XSS only appears in immediate responses like search results. A useful memory tip: think "store and serve"—if the payload is saved in a database and later displayed to others, it's stored XSS.

⚠ Common exam trap

Test-takers frequently confuse XSS with SQL injection because both involve injecting malicious input, but XSS targets the browser's execution context while SQL injection targets the database query layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cross-site scripting

The tester's input <script>alert(1)</script> is executed in the browser, which is the classic symptom of a stored (persistent) cross-site scripting (XSS) vulnerability. The web form fails to sanitize or encode user-supplied data before storing it and later rendering it in other users' browsers, allowing arbitrary JavaScript to run in the security context of the application's origin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SQL injection

    Why it's wrong here

    SQL injection targets database queries, not browser execution of injected script code.

  • Cross-site request forgery

    Why it's wrong here

    CSRF tricks a logged-in user into making unwanted actions, not running injected script.

  • Cross-site scripting

    Why this is correct

    The application reflects untrusted input into a page without proper encoding, allowing script execution.

  • Command injection

    Why it's wrong here

    Command injection abuses server-side OS commands, not JavaScript running in a browser.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company portal lets employees save a short profile bio. One employee enters a string containing script code, and later other users who view that profile are redirected to a fake sign-in page. What vulnerability best explains this behavior?

medium
  • A.Reflected cross-site scripting, because the payload only appears in the current request response.
  • B.Stored cross-site scripting, because the malicious script is saved and served to other users later.
  • C.Command injection, because the script runs inside the web server process.
  • D.Session fixation, because the attacker wants the victim to use an old session ID.

Why B: The employee's profile bio is saved to the server and later served to other users who view the profile. This is the defining characteristic of stored (persistent) cross-site scripting (XSS): the malicious script is permanently stored on the target server and executed in the browsers of other users when they retrieve the stored data.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.