Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester is performing a web application test and wants to exploit a SQL injection vulnerability to extract data from a database. The tester knows that the application returns results in the HTTP response. Which type of SQL injection is being used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

UNION-based

UNION-based SQL injection returns results directly in the application's output.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Blind boolean-based

    Why it's wrong here

    Boolean-based blind SQL injection does not return database rows in the HTTP response; instead, the attacker sends a condition that changes the application's logical result, such as a true/false clause. The response's content, status code, or page layout shifts subtly—like a 'Welcome' message appearing only when the condition is true—letting the tester infer data one bit at a time. This technique requires many requests to extract a single value, but it works when the application does not expose query output.

  • ✗

    Blind time-based

    Why it's wrong here

    Time-based blind SQL injection forces the database itself to pause for a fixed duration using functions like SLEEP() or WAITFOR DELAY when a condition is true. Since the HTTP response is delayed accordingly, the tester measures the elapsed time to answer a yes/no question about the data, without ever seeing the data itself in the HTML. It is highly valuable when the application suppresses error messages and shows identical page content regardless of the query's result, but it is slower and can be disrupted by network jitter or timeouts.

  • ✗

    Out-of-band

    Why it's wrong here

    Out-of-band SQL injection uses a secondary communication channel to exfiltrate results, because the application neither reflects the data in the response nor provides a usable boolean or timing oracle. The attacker crafts a payload that triggers an external request—often to a DNS server they control—with sensitive data embedded in the subdomain, such as 'secret.example.com' resolved by a lookup. This technique requires the database server to have network egress and the attacker to run an authoritative listener, but it can extract large volumes of data efficiently in one shot.

  • ✓

    UNION-based

    Why this is correct

    UNION-based SQL injection directly concatenates the attacker's injected SELECT statement to the original query using the UNION operator, so the modified result set is rendered in the HTTP response. The tester determines the exact number of columns and then selects the wanted columns from arbitrary tables (e.g., usernames and passwords) which appear as rows in the page. Because the data is returned in-band, this is the fastest and simplest method, and it also aids in retrieving system metadata like the DBMS version for further attacks.

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.