Courseiva

SSCP Network and Communications Security Practice Question

A security analyst is investigating a potential attack on a web application. The analyst observes that an attacker is sending specially crafted requests that cause the application to execute unintended commands on the underlying operating system. Which type of attack is this?

⚠ Common exam trap

Many exam-takers confuse command injection with SQL injection, as both involve injecting malicious input, but only command injection leads to OS command execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command injection

Command injection is the correct answer because the scenario describes an attacker causing the application to execute unintended operating system commands. This occurs when user input is passed to a system shell without proper sanitization. XSS targets the browser, SQL injection targets the database, and CSRF tricks the user's browser into making requests. None of these directly result in OS command execution as described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection involves inserting malicious SQL statements into input fields to manipulate a database. While it can sometimes lead to command execution if the database supports it, the scenario explicitly mentions execution of operating system commands, which is more characteristic of command injection. SQL injection primarily targets the database, not the OS, unless combined with other vulnerabilities.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    XSS attacks target the user's browser by injecting malicious scripts into web pages viewed by other users. The scenario describes execution of commands on the server's operating system, not in a user's browser. XSS does not typically result in OS command execution on the server. Therefore, this is not the correct attack type.

  • ✓

    Command injection

    Why this is correct

    Command injection occurs when an application passes unsafe user input to a system shell, allowing an attacker to execute arbitrary commands on the host operating system. The scenario describes crafted requests causing unintended OS command execution, which is the definition of command injection. This vulnerability often arises when applications use functions like system() or exec() without proper input sanitization.

  • ✗

    Cross-site request forgery (CSRF)

    Why it's wrong here

    CSRF tricks a user's browser into sending unauthorized requests to a web application where the user is authenticated. It does not involve executing OS commands on the server. The scenario describes direct OS command execution, not forced actions by a user. CSRF exploits the trust a site has in the user's browser, not server-side command execution.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.