PT0-002 Attacks and Exploits Practice Question
A penetration tester is performing a web application test and wants to exploit a SQL injection vulnerability to extract data from a database. The tester knows that the application returns results in the HTTP response. Which type of SQL injection is being used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UNION-based
UNION-based SQL injection returns results directly in the application's output.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Blind boolean-based
Why it's wrong here
Boolean-based blind SQL injection does not return database rows in the HTTP response; instead, the attacker sends a condition that changes the application's logical result, such as a true/false clause. The response's content, status code, or page layout shifts subtly—like a 'Welcome' message appearing only when the condition is true—letting the tester infer data one bit at a time. This technique requires many requests to extract a single value, but it works when the application does not expose query output.
- ✗
Blind time-based
Why it's wrong here
Time-based blind SQL injection forces the database itself to pause for a fixed duration using functions like SLEEP() or WAITFOR DELAY when a condition is true. Since the HTTP response is delayed accordingly, the tester measures the elapsed time to answer a yes/no question about the data, without ever seeing the data itself in the HTML. It is highly valuable when the application suppresses error messages and shows identical page content regardless of the query's result, but it is slower and can be disrupted by network jitter or timeouts.
- ✗
Out-of-band
Why it's wrong here
Out-of-band SQL injection uses a secondary communication channel to exfiltrate results, because the application neither reflects the data in the response nor provides a usable boolean or timing oracle. The attacker crafts a payload that triggers an external request—often to a DNS server they control—with sensitive data embedded in the subdomain, such as 'secret.example.com' resolved by a lookup. This technique requires the database server to have network egress and the attacker to run an authoritative listener, but it can extract large volumes of data efficiently in one shot.
- ✓
UNION-based
Why this is correct
UNION-based SQL injection directly concatenates the attacker's injected SELECT statement to the original query using the UNION operator, so the modified result set is rendered in the HTTP response. The tester determines the exact number of columns and then selects the wanted columns from arbitrary tables (e.g., usernames and passwords) which appear as rows in the page. Because the data is returned in-band, this is the fastest and simplest method, and it also aids in retrieving system metadata like the DBMS version for further attacks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.