hardMultiple Choice
SSCP Practice Question: A security analyst reviews logs and finds that an…
A security analyst reviews logs and finds that an attacker exploited a vulnerability in a web application to read arbitrary files from the server. The application runs on Apache with mod_php. Which of the following is the MOST likely vulnerability?
⚠ Common exam trap
Many exam-takers confuse LFI with RFI because both involve file inclusion, but the key distinction is that LFI reads local files from the server, while RFI requires remote file inclusion, which is less common and often blocked by default PHP settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local File Inclusion (LFI) vulnerability in a PHP include statement.
The scenario describes reading arbitrary files from the server, which is the hallmark of a Local File Inclusion (LFI) vulnerability. In a PHP application using include statements, an attacker can manipulate a file path parameter (e.g., `?page=../../etc/passwd`) to include and read local files, exploiting the server's filesystem access. Apache with mod_php is particularly susceptible to LFI when user input is not sanitized before being passed to functions like `include()` or `require()`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
XML External Entity (XXE) vulnerability.
Why it's wrong here
XXE requires an XML parser processing attacker-supplied documents with external entity resolution enabled; mod_php reading arbitrary files points instead to path traversal or injection flaws. XXE is tempting because it also yields file disclosure, and would be correct where the application parses uploaded XML or SOAP requests with entity expansion permitted.
- ✗
Remote File Inclusion (RFI) vulnerability.
Why it's wrong here
RFI pulls a remote file into execution via an inclusion parameter; reading arbitrary local files is instead Local File Inclusion or path traversal. RFI fits scenarios where an attacker hosts a malicious script externally and the application fetches it.
- ✗
Server-Side Request Forgery (SSRF) vulnerability.
Why it's wrong here
SSRF makes the server issue outbound requests to internal or external resources; it does not itself return local file contents to the attacker. SSRF is the right answer when the target is an internal metadata endpoint or otherwise unreachable service.
- ✓
Local File Inclusion (LFI) vulnerability in a PHP include statement.
Why this is correct
PHP include statements that accept user-supplied paths without validation let an attacker traverse the filesystem and read arbitrary files. Because the application runs mod_php, a Local File Inclusion flaw in an include call is the most likely mechanism enabling the observed arbitrary file reads.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.