What Is Stored (Persistent) XSS?
A web form stores a user's comment and later displays it to other users. A tester submits <script>alert(1)</script> and the script runs in the browser. What vulnerability is this?
Quick Answer
The answer is stored (persistent) cross-site scripting (XSS). This is correct because the malicious script, `<script>alert(1)</script>`, is submitted through a web form, stored on the server, and then executed in the browsers of other users who view the comment—this persistence on the server side is what distinguishes stored XSS from reflected or DOM-based variants. On the Security+ SY0-701 exam, this scenario tests your understanding of input validation and output encoding failures; a common trap is confusing stored XSS with reflected XSS, but remember that stored XSS involves data that is permanently saved and served to multiple users, while reflected XSS only appears in immediate responses like search results. A useful memory tip: think "store and serve"—if the payload is saved in a database and later displayed to others, it's stored XSS.
⚠ Common exam trap
Test-takers frequently confuse XSS with SQL injection because both involve injecting malicious input, but XSS targets the browser's execution context while SQL injection targets the database query layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cross-site scripting
The tester's input <script>alert(1)</script> is executed in the browser, which is the classic symptom of a stored (persistent) cross-site scripting (XSS) vulnerability. The web form fails to sanitize or encode user-supplied data before storing it and later rendering it in other users' browsers, allowing arbitrary JavaScript to run in the security context of the application's origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection
Why it's wrong here
SQL injection targets database queries, not browser execution of injected script code.
- ✗
Cross-site request forgery
Why it's wrong here
CSRF tricks a logged-in user into making unwanted actions, not running injected script.
- ✓
Cross-site scripting
Why this is correct
The application reflects untrusted input into a page without proper encoding, allowing script execution.
- ✗
Command injection
Why it's wrong here
Command injection abuses server-side OS commands, not JavaScript running in a browser.
Go deeper
Related to this question
Learn chapter
Application Attacks: SQL Injection, XSS
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Cross-site scripting
Cross-site scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users, often to steal data or hijack sessions.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company portal lets employees save a short profile bio. One employee enters a string containing script code, and later other users who view that profile are redirected to a fake sign-in page. What vulnerability best explains this behavior?
medium- A.Reflected cross-site scripting, because the payload only appears in the current request response.
- ✓ B.Stored cross-site scripting, because the malicious script is saved and served to other users later.
- C.Command injection, because the script runs inside the web server process.
- D.Session fixation, because the attacker wants the victim to use an old session ID.
Why B: The employee's profile bio is saved to the server and later served to other users who view the profile. This is the defining characteristic of stored (persistent) cross-site scripting (XSS): the malicious script is permanently stored on the target server and executed in the browsers of other users when they retrieve the stored data.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.