Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIAPenTest+

Domain 4Objective 4

Web Application Attacks PT0-003 Practice Questions (Page 1)

Part of the Attacks and exploits domain, which accounts for 35% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~23–39 in this domain), expect 4–7 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
9concepts
35%of the exam

Questions 1–5

  1. 1foundation · easy

    Which of the following is a common sign that a web application may be vulnerable to XSS?

    Select an answer first
  2. 2application · medium

    A penetration tester discovers a comment section on a public blog that reflects user input without sanitization. The tester wants to steal the session cookies of other users. Which of the following payloads would be MOST effective for this purpose?

    Select an answer first
  3. 3foundation · easy

    What is the primary goal of an attacker when exploiting a stored XSS vulnerability?

    Select an answer first
  4. 4foundation · easy

    Which of the following best describes how a classic SQL injection attack works?

    Select an answer first
  5. 5application · medium

    A tester is mapping a web application's attack surface. While reviewing the source code, the tester finds a search function that directly concatenates the user's search term into a SQL query. Which of the following is the MOST appropriate next step to confirm the vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.