exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 138 discussion

Actual exam question from CompTIA's PT0-001
Question #: 138
Topic #: 1
[All PT0-001 Questions]

A penetration tester has performed a vulnerability scan of a specific host that contains a valuable database and has identified the following vulnerabilities:
✑ XSS
✑ HTTP DELETE method allowed
✑ SQL injection
✑ Vulnerable to CSRF
To which of the following should the tester give the HIGHEST priority?

  • A. SQL injection
  • B. HTTP DELETE method allowed
  • C. Vulnerable to CSRF
  • D. XSS
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
miabe
2 years, 10 months ago
Selected Answer: A
looks good to me
upvoted 1 times
...
likeahoss
3 years, 6 months ago
Does anyone know what could be deleted with HTTP DELETE method? Could it potentially reach back to the DB and delete everything? I would assume just HTTP objects, but what do I know.
upvoted 2 times
...
smalltech
3 years, 9 months ago
A.https://owasp.org/www-project-top-ten/
upvoted 1 times
...
CapCrunch
3 years, 10 months ago
B. As part of the CIA triad you would want to ensure data integrity
upvoted 3 times
anonamphibian
3 years, 2 months ago
To further support this , HTTP DELETE method allows for the deletion of any content or code which would cause data integrity to be lost. where as the inject just retrieves the content. Furthermore HTTP delete could also cause loss of availability as well if the right code segment is deleted.
upvoted 1 times
...
...
nonyabiz
3 years, 10 months ago
First, Comptia is piggy backing their rankings off of the OWASP top 10. The #1 vuln on the OWASP top 10 is SQL injection, not XSS: Top 10 Web Application Security Risks A1:2017-Injection: Injection flaws, such as SQL, NoSQL, OS, and LDAP injection, occur when untrusted data is sent to an interpreter as part of a command or query. The attacker’s hostile data can trick the interpreter into executing unintended commands or accessing data without proper authorization. With that in mind and the obvious reference to a "vulnerable database", this should be SQL injection.
upvoted 3 times
...
TheThreatGuy
4 years, 4 months ago
I believe we should focus on "contains a valuable database". Although XSS is considered a more dangerous attack, we would be more concerned with gaining access to the database via SQL injection. So A.
upvoted 4 times
varo82
3 years, 11 months ago
I think that you have right!
upvoted 1 times
...
ufovictim
4 years, 3 months ago
Agreed - normally XSS is a given for “most critical” on CompTIA exams but I think they’re mixing it up since this is specifically for a database. An SQL injection could delete the entire thing or allow an attacker to exfiltrate data. Going with A
upvoted 1 times
...
...
someguy1393
4 years, 5 months ago
I also think A. I believe that Stored XSS is considered the #1 priority by Comptia.
upvoted 1 times
...
jossephh
4 years, 5 months ago
I agree on A based on https://developer.mozilla.org/en-US/docs/Web/HTTP/Methods/DELETE the command will delete the specified resource (HTML or PHP), but an SQLi vulnerability could DROP the whole database, surely more devastating
upvoted 2 times
anonamphibian
3 years, 2 months ago
HTTP Delete can also drop the DB as well.
upvoted 1 times
...
...
Vaios
4 years, 7 months ago
I would say A or D but more towards A . Why is B ? why someone would want to delete ?
upvoted 1 times
...
GreyHunter
4 years, 7 months ago
I guess A is the correct answer.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago