Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester is exploiting a SQL injection vulnerability in a web application. They want to extract data from the database without displaying it on the page. Which SQL injection technique should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blind time-based SQL injection

Blind SQL injection techniques like time-based or boolean-based are used when data is not returned directly in the response. Time-based uses delays to infer information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Blind time-based SQL injection

    Why this is correct

    This attack works by injecting a conditional clause that pauses the database response only when a predicate evaluates true, such as `IF(ASCII(SUBSTR((SELECT database()),1,1))>100, SLEEP(5), 0)`. Since the application never directly prints the query output, the tester infers each character by measuring response-delay differences, extracting data one bit or one character at a time without needing visible rows or error messages. It is the only technique among the choices that succeeds when the application suppresses both output and errors, which matches the scenario described.

  • ✗

    Stacked queries

    Why it's wrong here

    Stacked queries rely on the ability to append a second SQL statement after a semicolon, e.g., `SELECT ...; DROP TABLE users;`, which is often blocked by parameterized APIs or statement separators. Even when they execute, they return no additional result set to the application, so they provide no way to read the injected query's output; they would only be useful for causing side effects or for time-based inference if combined with a delay. In this context, they do not satisfy the requirement of retrieving data, so they are incorrect.

  • ✗

    UNION-based SQL injection

    Why it's wrong here

    UNION-based injection needs the original query's result set to be displayed to the attacker, because it appends row(s) with matching column counts and types to the legitimate output. This requires the application to render the query's results in the HTTP response, and it also requires probing the number of columns and data types. Since the question states no visible output is available, the UNION approach cannot be used to infer data, making it a poor fit compared with the blind time-based method that works without any reflected output.

  • ✗

    Error-based SQL injection

    Why it's wrong here

    Error-based injection exploits database error messages that are generated by malformed queries or functions like `extractvalue` and `updatexml`, causing the database engine to include part of the attacker's data in the returned error text. If the application has disabled verbose database errors, shows a generic error page, or uses an exception-driven pattern that suppresses the message, the attacker receives no usable information. The scenario does not mention any accessible error output, so error-based SQLi cannot provide the exfiltration channel that the time-based technique supplies.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.