Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A security analyst is reviewing a vulnerability scan report for a web application. The report shows a high-severity finding for a SQL injection vulnerability on a login page. The analyst needs to validate the finding before escalating to the development team. Which of the following actions should the analyst take to safely validate the vulnerability?

⚠ Common exam trap

The trap here is thinking that exploiting the vulnerability (e.g., dumping the schema) is necessary for validation, when a simple error-based test is sufficient and safer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Manually inject a benign SQL payload that returns a database error, such as a single quote.

Manual injection of a benign payload like a single quote is a safe and effective way to validate SQL injection. It tests the application's input handling without extracting data or causing damage. If a database error is returned, the vulnerability is confirmed. This approach is minimally invasive and suitable for production systems, allowing the analyst to escalate with confidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full vulnerability scan with credentials to confirm the finding.

    Why it's wrong here

    Running a credentialed scan may provide more accurate results, but it does not directly validate this specific SQL injection finding. Credentialed scans are better for configuration issues and missing patches. For a web application vulnerability, manual testing is more appropriate. Additionally, a full scan could be time-consuming and may not replicate the exploit conditions.

  • ✗

    Use an automated SQL injection tool to dump the database schema.

    Why it's wrong here

    Dumping the database schema is an intrusive action that could expose sensitive data and violate ethical boundaries. It may also cause performance issues or trigger alerts. While it would confirm the vulnerability, it is not a safe validation method for a production system. The analyst should avoid actions that could compromise data integrity or confidentiality.

  • ✗

    Review the application source code for parameterized queries.

    Why it's wrong here

    Reviewing source code is a valid validation method, but it requires access to the code and may not be immediately available. The scenario implies the analyst is validating a scan finding, likely without direct code access. Manual injection testing is quicker and directly confirms the vulnerability in the running application, which is the immediate concern.

  • ✓

    Manually inject a benign SQL payload that returns a database error, such as a single quote.

    Why this is correct

    Injecting a single quote is a safe, non-destructive way to test for SQL injection. If the application returns a database error, it indicates improper input sanitization and potential SQL injection. This method validates the finding without extracting data or modifying the database, making it suitable for a production environment. It is a standard manual validation technique.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.