Courseiva
mediumMultiple Select

PT0-002 Practice Question: A penetration tester is analyzing a network…

A penetration tester is analyzing a network packet capture to identify potential attacks. Which two indicators suggest a successful SQL injection attempt?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A query string containing ' OR 1=1--

Option C is correct because a query string containing ' OR 1=1-- is a classic SQL injection payload: the single quote breaks out of the intended string literal, OR 1=1 makes the WHERE clause always true, and -- comments out the remainder of the original query, so its presence in captured HTTP traffic is a strong indicator of an injection attempt. Option D is correct because unexpected data in the response body (for example, database error messages, extra rows, or records the application should not return) indicates the injected SQL was actually executed and influenced the query result, which distinguishes a successful injection from a mere attempt. The other options are not specific to SQL injection: A (multiple failed login attempts) points to brute-force or credential-stuffing activity, B (a large number of HTTP 500 errors) is a generic sign of server-side faults or fuzzing that may accompany many attack types, and E (a significant increase in outbound traffic) suggests data exfiltration or command-and-control traffic rather than SQL injection itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multiple failed login attempts

    Why it's wrong here

    Repeated failed login attempts in a packet capture indicate an authentication brute-force or credential-stuffing attack, not SQL injection. SQL injection occurs within a single request's parameters (e.g., query string or POST body) and does not inherently require multiple failed attempts to succeed. The capture would show many authentication requests with invalid credentials and HTTP 401/403 responses, whereas SQLi would typically show a single crafted request that attempts to manipulate the underlying SQL query.

  • ✗

    A large number of HTTP 500 errors

    Why it's wrong here

    A large volume of HTTP 500 errors is a generic sign of server-side issues and is not diagnostic of SQL injection by itself. While a malformed SQLi payload can trigger database exceptions that result in 500 responses, many other factors—such as application bugs, misconfigurations, or resource exhaustion—produce the same status code. Moreover, successful SQL injection often returns a 200 OK with altered content, so relying on 500s fail to detect the most common injection outcomes.

  • ✓

    A query string containing ' OR 1=1--

    Why this is correct

    The query string containing ' OR 1=1-- is the classic tautology-based SQL injection payload. The single quote terminates the SQL string literal in the WHERE clause, OR 1=1 makes the condition always true, and -- comments out the remainder of the original query, forcing the database to return more results than intended. In a network capture, this exact pattern in a GET request's query parameters is direct, technical evidence of a SQL injection attempt and is the most definitive indicator among the options.

  • ✓

    Unexpected data in the response body

    Why this is correct

    Unexpected data in the response body can be a symptom of successful SQL injection, such as when a UNION-based query causes database records to appear in an application's HTML output. However, this indicator is ambiguous because other flaws—like XML injection, command injection, or plain application errors—can also produce anomalous response content. Without correlating the unexpected data to a specific request containing SQL metacharacters, it remains only an indirect sign that warrants further investigation.

  • ✗

    A significant increase in outbound traffic

    Why it's wrong here

    A significant increase in outbound traffic is a broad network anomaly that could result from any data exfiltration activity, such as file uploads, backup transfers, or malware command-and-control beacons, not specifically SQL injection. In SQLi attacks, data extraction typically occurs within the normal HTTP response over the existing connection, so the overall outbound volume may not rise noticeably unless large datasets are being dumped. As a standalone metric, it lacks the specificity needed to point to a particular web application vulnerability.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.