CompTIA PenTest+ PT0-003 (V3) Practice Question

During a web application assessment of an online forum, a penetration tester suspects a stored cross-site scripting (XSS) vulnerability in the comment submission feature. The tester's initial attempts to inject a simple <script>alert(1)</script> payload are blocked by a basic input filter. Which of the following techniques is the most effective next step to confirm the vulnerability by attempting to bypass the filter?

  • Encode the entire <script> payload using URL encoding and resubmit it.

  • Inject a payload using a different HTML tag and an event handler, such as <img src=x onerror=alert('XSS')>.

  • Use an automated SQL injection tool's XSS module to find a valid payload.

  • Send the payload in an HTTP header like User-Agent to see if it is reflected elsewhere.

CompTIA PenTest+ PT0-003 (V3)
Attacks and Exploits
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA PenTest+ Voucher with Retake
v3 / PT0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot