PT0-002 Attacks and Exploits Practice Question
A penetration tester is exploiting a SQL injection vulnerability in a web application. They want to extract data from the database without displaying it on the page. Which SQL injection technique should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Blind time-based SQL injection
Blind SQL injection techniques like time-based or boolean-based are used when data is not returned directly in the response. Time-based uses delays to infer information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Blind time-based SQL injection
Why this is correct
This attack works by injecting a conditional clause that pauses the database response only when a predicate evaluates true, such as `IF(ASCII(SUBSTR((SELECT database()),1,1))>100, SLEEP(5), 0)`. Since the application never directly prints the query output, the tester infers each character by measuring response-delay differences, extracting data one bit or one character at a time without needing visible rows or error messages. It is the only technique among the choices that succeeds when the application suppresses both output and errors, which matches the scenario described.
- ✗
Stacked queries
Why it's wrong here
Stacked queries rely on the ability to append a second SQL statement after a semicolon, e.g., `SELECT ...; DROP TABLE users;`, which is often blocked by parameterized APIs or statement separators. Even when they execute, they return no additional result set to the application, so they provide no way to read the injected query's output; they would only be useful for causing side effects or for time-based inference if combined with a delay. In this context, they do not satisfy the requirement of retrieving data, so they are incorrect.
- ✗
UNION-based SQL injection
Why it's wrong here
UNION-based injection needs the original query's result set to be displayed to the attacker, because it appends row(s) with matching column counts and types to the legitimate output. This requires the application to render the query's results in the HTTP response, and it also requires probing the number of columns and data types. Since the question states no visible output is available, the UNION approach cannot be used to infer data, making it a poor fit compared with the blind time-based method that works without any reflected output.
- ✗
Error-based SQL injection
Why it's wrong here
Error-based injection exploits database error messages that are generated by malformed queries or functions like `extractvalue` and `updatexml`, causing the database engine to include part of the attacker's data in the returned error text. If the application has disabled verbose database errors, shows a generic error page, or uses an exception-driven pattern that suppresses the message, the attacker receives no usable information. The scenario does not mention any accessible error output, so error-based SQLi cannot provide the exfiltration channel that the time-based technique supplies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.