hardMultiple Choice
SSCP Practice Question: During a penetration test, an attacker was able…
During a penetration test, an attacker was able to bypass input validation and execute commands on a web server. The server runs a PHP application. Which of the following is the MOST likely root cause?
⚠ Common exam trap
Candidates often confuse command injection with SQL injection or XSS, but the key differentiator is the ability to execute OS-level commands on the server, which only occurs through shell execution functions like exec() or system().
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application passes user input to a shell command via exec() or system() functions.
The scenario describes command execution on the web server, which is a direct consequence of OS command injection. In PHP, passing unsanitized user input to functions like exec() or system() allows an attacker to execute arbitrary shell commands, bypassing input validation. This is the most likely root cause as it directly enables command execution, unlike other vulnerabilities that lead to different impacts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application uses unsanitized input in SQL queries.
Why it's wrong here
SQL injection manipulates database queries, not the shell, so it cannot execute OS commands on the web server. It is tempting because unsanitised input in SQL queries is a genuine, common flaw, and would be the correct root cause if the penetration tester had extracted or altered database records instead.
- ✗
The application reflects user input in HTTP responses without escaping.
Why it's wrong here
Reflecting unescaped input produces cross-site scripting in a victim's browser, not server-side command execution. It is tempting because reflected input is a genuine PHP flaw, and would be the correct root cause if the penetration tester had demonstrated script execution in another user's session rather than commands on the web server.
- ✓
The application passes user input to a shell command via exec() or system() functions.
Why this is correct
Passing unsanitised input into exec() or system() lets shell metacharacters spawn arbitrary OS commands, which is command injection rather than SQL injection or XSS. This directly explains bypassed input validation and code execution on the PHP host.
- ✗
The application uses hidden form fields to store session tokens.
Why it's wrong here
Hidden form fields storing session tokens enable token tampering and session hijacking, not command execution on the host. It is tempting because hidden fields are a real client-side weakness, and would be the correct root cause if the attacker had escalated privileges by editing a token value in the submitted form.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.