Courseiva

SSCP Systems and Application Security Practice Question

A security analyst is reviewing an application that accepts a user-supplied file path and uses it to read a configuration file from disk. The analyst observes that a user can enter ../../etc/passwd and the application returns the contents of that system file. Which of the following best describes this vulnerability?

⚠ Common exam trap

Candidates often confuse any unauthorized file or data access with insecure direct object reference, when the distinguishing feature of path traversal is the use of relative path sequences to escape the intended directory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Path traversal

The ability to enter ../ sequences and retrieve a file outside the intended directory is the defining behavior of path traversal. The application fails to canonicalize and validate the supplied path, allowing access to files such as /etc/passwd. The other choices describe client-side script injection, object identifier manipulation, or forced server requests, none of which match the observed file-read behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server-side request forgery

    Why it's wrong here

    Server-side request forgery tricks the server into making HTTP requests to unintended internal or external destinations. The scenario describes reading a local file through a manipulated path, not causing the server to issue network requests. The absence of any outbound request means SSRF does not describe this vulnerability.

  • ✗

    Insecure direct object reference

    Why it's wrong here

    Insecure direct object reference involves exposing an internal identifier such as a record number and allowing a user to access objects belonging to others by changing that identifier. The scenario involves manipulating a filesystem path with traversal sequences, not altering a direct object identifier. While both are access-control failures, the mechanism described is path traversal.

  • ✓

    Path traversal

    Why this is correct

    Path traversal, also called directory traversal, occurs when user-supplied input containing sequences like ../ is used to access files outside the intended directory. The analyst's observation that ../../etc/passwd returns a system file demonstrates exactly this flaw. The application fails to validate or normalize the path, allowing access to arbitrary files readable by the process.

  • ✗

    Cross-site scripting

    Why it's wrong here

    Cross-site scripting occurs when untrusted input is reflected into a web page and executed in a victim's browser, affecting client-side sessions. Here the issue is server-side file access using a manipulated path, with no script execution in a browser. The described behavior does not match XSS, so this choice is incorrect.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.