CAS-004 Security Operations Practice Question
A security analyst is reviewing a vulnerability scan report for a web application. The report shows a high-severity finding for a SQL injection vulnerability on a login page. The analyst needs to validate the finding before escalating to the development team. Which of the following actions should the analyst take to safely validate the vulnerability?
⚠ Common exam trap
The trap here is thinking that exploiting the vulnerability (e.g., dumping the schema) is necessary for validation, when a simple error-based test is sufficient and safer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manually inject a benign SQL payload that returns a database error, such as a single quote.
Manual injection of a benign payload like a single quote is a safe and effective way to validate SQL injection. It tests the application's input handling without extracting data or causing damage. If a database error is returned, the vulnerability is confirmed. This approach is minimally invasive and suitable for production systems, allowing the analyst to escalate with confidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full vulnerability scan with credentials to confirm the finding.
Why it's wrong here
Running a credentialed scan may provide more accurate results, but it does not directly validate this specific SQL injection finding. Credentialed scans are better for configuration issues and missing patches. For a web application vulnerability, manual testing is more appropriate. Additionally, a full scan could be time-consuming and may not replicate the exploit conditions.
- ✗
Use an automated SQL injection tool to dump the database schema.
Why it's wrong here
Dumping the database schema is an intrusive action that could expose sensitive data and violate ethical boundaries. It may also cause performance issues or trigger alerts. While it would confirm the vulnerability, it is not a safe validation method for a production system. The analyst should avoid actions that could compromise data integrity or confidentiality.
- ✗
Review the application source code for parameterized queries.
Why it's wrong here
Reviewing source code is a valid validation method, but it requires access to the code and may not be immediately available. The scenario implies the analyst is validating a scan finding, likely without direct code access. Manual injection testing is quicker and directly confirms the vulnerability in the running application, which is the immediate concern.
- ✓
Manually inject a benign SQL payload that returns a database error, such as a single quote.
Why this is correct
Injecting a single quote is a safe, non-destructive way to test for SQL injection. If the application returns a database error, it indicates improper input sanitization and potential SQL injection. This method validates the finding without extracting data or modifying the database, making it suitable for a production environment. It is a standard manual validation technique.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.