What Is Stored (Persistent) XSS?
A web form stores a user's comment and later displays it to other users. A tester submits <script>alert(1)</script> and the script runs in the browser. What vulnerability is this?
Quick Answer
The answer is stored (persistent) cross-site scripting (XSS). This is correct because the malicious script, `<script>alert(1)</script>`, is submitted through a web form, stored on the server, and then executed in the browsers of other users who view the comment—this persistence on the server side is what distinguishes stored XSS from reflected or DOM-based variants. On the Security+ SY0-701 exam, this scenario tests your understanding of input validation and output encoding failures; a common trap is confusing stored XSS with reflected XSS, but remember that stored XSS involves data that is permanently saved and served to multiple users, while reflected XSS only appears in immediate responses like search results. A useful memory tip: think "store and serve"—if the payload is saved in a database and later displayed to others, it's stored XSS.
⚠ Common exam trap
Test-takers frequently confuse XSS with SQL injection because both involve injecting malicious input, but XSS targets the browser's execution context while SQL injection targets the database query layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cross-site scripting
The tester's input <script>alert(1)</script> is executed in the browser, which is the classic symptom of a stored (persistent) cross-site scripting (XSS) vulnerability. The web form fails to sanitize or encode user-supplied data before storing it and later rendering it in other users' browsers, allowing arbitrary JavaScript to run in the security context of the application's origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection
Why it's wrong here
SQL injection manipulates database queries through unsanitised input; the submitted script executed in the browser rather than altering a query, so this is cross-site scripting. SQL injection is tempting because the comment is stored, but the defining mechanism here is script execution on output.
- ✗
Cross-site request forgery
Why it's wrong here
Cross-site request forgery tricks an authenticated browser into sending unwanted requests; it does not involve injecting script that executes in the page. It is tempting because both are browser-side web flaws, but CSRF exploits ambient session cookies, whereas this payload is stored and rendered as executable script.
- ✓
Cross-site scripting
Why this is correct
The submitted script executes in another user's browser because the comment is rendered without output encoding, which is reflected or stored cross-site scripting. The payload running client-side, rather than server-side execution, distinguishes XSS from injection flaws such as SQL injection.
- ✗
Command injection
Why it's wrong here
Command injection executes operating-system commands on the server; the payload here is JavaScript executing in the victim's browser, which is cross-site scripting. Command injection is tempting because both involve injecting attacker-controlled input, but it targets shell execution, not reflected script rendering.
Go deeper
Related to this question
Learn chapter
IoT Security Vulnerabilities
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Cross-site scripting
Cross-site scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users, often to steal data or hijack sessions.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company portal lets employees save a short profile bio. One employee enters a string containing script code, and later other users who view that profile are redirected to a fake sign-in page. What vulnerability best explains this behavior?
medium- A.Reflected cross-site scripting, because the payload only appears in the current request response.
- ✓ B.Stored cross-site scripting, because the malicious script is saved and served to other users later.
- C.Command injection, because the script runs inside the web server process.
- D.Session fixation, because the attacker wants the victim to use an old session ID.
Why B: The employee's profile bio is saved to the server and later served to other users who view the profile. This is the defining characteristic of stored (persistent) cross-site scripting (XSS): the malicious script is permanently stored on the target server and executed in the browsers of other users when they retrieve the stored data.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.