SSCP Network and Communications Security Practice Question
A security analyst is investigating a potential attack on a web application. The analyst observes that an attacker is sending specially crafted requests that cause the application to execute unintended commands on the underlying operating system. Which type of attack is this?
⚠ Common exam trap
Many exam-takers confuse command injection with SQL injection, as both involve injecting malicious input, but only command injection leads to OS command execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Command injection
Command injection is the correct answer because the scenario describes an attacker causing the application to execute unintended operating system commands. This occurs when user input is passed to a system shell without proper sanitization. XSS targets the browser, SQL injection targets the database, and CSRF tricks the user's browser into making requests. None of these directly result in OS command execution as described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SQL injection
Why it's wrong here
SQL injection involves inserting malicious SQL statements into input fields to manipulate a database. While it can sometimes lead to command execution if the database supports it, the scenario explicitly mentions execution of operating system commands, which is more characteristic of command injection. SQL injection primarily targets the database, not the OS, unless combined with other vulnerabilities.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
XSS attacks target the user's browser by injecting malicious scripts into web pages viewed by other users. The scenario describes execution of commands on the server's operating system, not in a user's browser. XSS does not typically result in OS command execution on the server. Therefore, this is not the correct attack type.
- ✓
Command injection
Why this is correct
Command injection occurs when an application passes unsafe user input to a system shell, allowing an attacker to execute arbitrary commands on the host operating system. The scenario describes crafted requests causing unintended OS command execution, which is the definition of command injection. This vulnerability often arises when applications use functions like system() or exec() without proper input sanitization.
- ✗
Cross-site request forgery (CSRF)
Why it's wrong here
CSRF tricks a user's browser into sending unauthorized requests to a web application where the user is authenticated. It does not involve executing OS commands on the server. The scenario describes direct OS command execution, not forced actions by a user. CSRF exploits the trust a site has in the user's browser, not server-side command execution.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.