Courseiva
Web Application Attacks →easyMultiple Choice

PEN-200 Web Application Attacks Practice Question

Which of the following describes a successful Path Traversal attack in a web application?

⚠ Common exam trap

Candidates often confuse Path Traversal with other vulnerabilities like Local File Inclusion (LFI), though they are related, the specific mechanism involves escaping directories using dot-dot-slash sequences.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using dot-dot-slash sequences to read /etc/passwd on a Linux server.

Path Traversal allows attackers to access files outside the intended web root directory by manipulating input parameters that contain file paths. By using dot-dot-slash sequences, an attacker escapes the restricted directory. This is a critical vulnerability that can lead to the exposure of configuration files, sensitive system data, or source code, which is why validating input is a fundamental security requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Injecting JavaScript into a form field to capture user session cookies.

    Why it's wrong here

    This describes a Cross-Site Scripting (XSS) attack, which targets client-side execution rather than file system access. It does not involve traversing directories or accessing restricted files, making it distinct from Path Traversal, which focuses on server-side file system manipulation.

  • ✓

    Using dot-dot-slash sequences to read /etc/passwd on a Linux server.

    Why this is correct

    This is the classic example of a Path Traversal attack. By moving up the directory tree using '..', the attacker can point the application to sensitive files like /etc/passwd that reside outside the intended document root, effectively bypassing access controls.

  • ✗

    Submitting a crafted SQL query to retrieve data from the database.

    Why it's wrong here

    This is a SQL Injection (SQLi) attack. It targets the database layer rather than the file system. While both are critical vulnerabilities, SQLi specifically exploits the way user data is handled in database queries, whereas Path Traversal exploits file retrieval processes.

  • ✗

    Overloading the server with requests to exhaust system memory.

    Why it's wrong here

    This describes a Denial of Service (DoS) attack. The goal here is to disrupt service availability rather than access sensitive information or traverse the file system. It relies on resource consumption rather than directory manipulation or input validation flaws.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.