Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA PT0-003 Exam - Topic 1 Question 40 Discussion

A penetration tester is conducting an assessment of a web application's login page. The tester needs to determine whether there are any hidden form fields of interest. Which of the following is the most effective technique?
D) HTML scraping
A) XSS
B) On-path attack
C) SQL injection

CompTIA PT0-003 Exam - Topic 1 Question 40 Discussion

Actual exam question for CompTIA's PT0-003 exam
Question #: 40
Topic #: 1
[All PT0-003 Questions]

A penetration tester is conducting an assessment of a web application's login page. The tester needs to determine whether there are any hidden form fields of interest. Which of the following is the most effective technique?

Show Suggested Answer Hide Answer
Suggested Answer: D

Hidden form fields in web applications can store user roles, session tokens, and security parameters that attackers may exploit.

HTML scraping (Option D):

Involves analyzing HTML source code to find hidden fields like:

<input type='hidden' name='admin_access' value='true'>

Attackers use tools like Burp Suite, ZAP, or browser developer tools (Ctrl+U or Inspect Element) to locate hidden fields.


Incorrect options:

Option A (XSS): Exploits JavaScript injection, not for finding hidden fields.

Option B (On-path attack): Involves MITM interception, not directly analyzing form fields.

Option C (SQL injection): Targets databases, not HTML forms

Contribute your Thoughts:

0/2000 characters
Craig
5 hours ago
On-path attack? Too complex for this task.
upvoted 0 times
...
Willis
5 days ago
XSS could be useful, but not for this.
upvoted 0 times
...
Coletta
11 days ago
Agreed, it reveals hidden fields easily.
upvoted 0 times
...
Marisha
16 days ago
I think HTML scraping is the best choice.
upvoted 0 times
...
Stefania
21 days ago
On-path attack seems a bit off for this scenario.
upvoted 0 times
...
Willis
26 days ago
Surprised that people still overlook HTML scraping!
upvoted 0 times
...
Brittni
1 month ago
Definitely not SQL injection for this task.
upvoted 0 times
...
Abel
1 month ago
I think XSS could also reveal some hidden data.
upvoted 0 times
...
Macy
1 month ago
HTML scraping is the way to go for hidden fields!
upvoted 0 times
...
Sherell
2 months ago
I thought HTML scraping was outdated, but it still works well!
upvoted 0 times
...
Annalee
2 months ago
Wait, are we really considering SQL injection for this? Seems off.
upvoted 0 times
...
Novella
2 months ago
On-path attacks can be effective, but not the best choice here.
upvoted 0 times
...
Viki
2 months ago
I disagree, XSS can reveal a lot too!
upvoted 0 times
...
Ammie
2 months ago
HTML scraping is definitely the way to go for hidden fields.
upvoted 0 times
...
Geoffrey
2 months ago
On-path attacks seem more about intercepting data rather than discovering hidden elements, so I’m leaning towards HTML scraping.
upvoted 0 times
...
Annabelle
3 months ago
I practiced a similar question where SQL injection was the focus, but I don't think it applies to finding hidden fields.
upvoted 0 times
...
Erin
3 months ago
I'm not really sure, but I remember something about XSS being related to input fields. Could that be relevant here?
upvoted 0 times
...
Vashti
3 months ago
I think HTML scraping might be the right choice since it involves analyzing the page structure for hidden fields.
upvoted 0 times
...

Save Cancel