CompTIA CySA+ CS0-003 (V3) Practice Question

A cybersecurity analyst is evaluating a new e-commerce web application. While testing the product search functionality, the analyst inputs a string containing a single quote ('). The application responds with an HTTP 500 error page displaying the message: "Syntax error in query expression 'ProductID = 'abc'' AND SearchText LIKE '%test'%' ". Based on this output, the analyst determines that user-supplied input is not being properly handled before being incorporated into a backend query. Which of the following vulnerabilities has the analyst most likely identified?

  • Remote code execution (RCE)

  • Cross-site scripting (XSS)

  • SQL injection

  • XML external entity (XXE) attack

CompTIA CySA+ CS0-003 (V3)
Vulnerability Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Cybersecurity Analyst Voucher with Retake
CySA+ / v3 / CS0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot