mediumMultiple Select
PT0-002 Practice Question: A penetration tester is analyzing a network…
A penetration tester is analyzing a network packet capture to identify potential attacks. Which two indicators suggest a successful SQL injection attempt?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A query string containing ' OR 1=1--
Option C is correct because a query string containing ' OR 1=1-- is a classic SQL injection payload: the single quote breaks out of the intended string literal, OR 1=1 makes the WHERE clause always true, and -- comments out the remainder of the original query, so its presence in captured HTTP traffic is a strong indicator of an injection attempt. Option D is correct because unexpected data in the response body (for example, database error messages, extra rows, or records the application should not return) indicates the injected SQL was actually executed and influenced the query result, which distinguishes a successful injection from a mere attempt. The other options are not specific to SQL injection: A (multiple failed login attempts) points to brute-force or credential-stuffing activity, B (a large number of HTTP 500 errors) is a generic sign of server-side faults or fuzzing that may accompany many attack types, and E (a significant increase in outbound traffic) suggests data exfiltration or command-and-control traffic rather than SQL injection itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Multiple failed login attempts
Why it's wrong here
Repeated failed login attempts in a packet capture indicate an authentication brute-force or credential-stuffing attack, not SQL injection. SQL injection occurs within a single request's parameters (e.g., query string or POST body) and does not inherently require multiple failed attempts to succeed. The capture would show many authentication requests with invalid credentials and HTTP 401/403 responses, whereas SQLi would typically show a single crafted request that attempts to manipulate the underlying SQL query.
- ✗
A large number of HTTP 500 errors
Why it's wrong here
A large volume of HTTP 500 errors is a generic sign of server-side issues and is not diagnostic of SQL injection by itself. While a malformed SQLi payload can trigger database exceptions that result in 500 responses, many other factors—such as application bugs, misconfigurations, or resource exhaustion—produce the same status code. Moreover, successful SQL injection often returns a 200 OK with altered content, so relying on 500s fail to detect the most common injection outcomes.
- ✓
A query string containing ' OR 1=1--
Why this is correct
The query string containing ' OR 1=1-- is the classic tautology-based SQL injection payload. The single quote terminates the SQL string literal in the WHERE clause, OR 1=1 makes the condition always true, and -- comments out the remainder of the original query, forcing the database to return more results than intended. In a network capture, this exact pattern in a GET request's query parameters is direct, technical evidence of a SQL injection attempt and is the most definitive indicator among the options.
- ✓
Unexpected data in the response body
Why this is correct
Unexpected data in the response body can be a symptom of successful SQL injection, such as when a UNION-based query causes database records to appear in an application's HTML output. However, this indicator is ambiguous because other flaws—like XML injection, command injection, or plain application errors—can also produce anomalous response content. Without correlating the unexpected data to a specific request containing SQL metacharacters, it remains only an indirect sign that warrants further investigation.
- ✗
A significant increase in outbound traffic
Why it's wrong here
A significant increase in outbound traffic is a broad network anomaly that could result from any data exfiltration activity, such as file uploads, backup transfers, or malware command-and-control beacons, not specifically SQL injection. In SQLi attacks, data extraction typically occurs within the normal HTTP response over the existing connection, so the overall outbound volume may not rise noticeably unless large datasets are being dumped. As a standalone metric, it lacks the specificity needed to point to a particular web application vulnerability.
Go deeper
Related to this question
Learn chapter
IDOR and Broken Access Control
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
Key term
Payload
In IT and cybersecurity, a payload is the core data or malicious code delivered within a packet, file, or attack that performs the actual intended action.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.