Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A tester is exploiting a vulnerable web application and wants to perform a UNION-based SQL injection to extract data. Which condition is necessary for a successful UNION attack?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The number of columns in both queries must match

UNION-based injection requires the same number of columns between the original query and the injected SELECT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The database must be MySQL

    Why it's wrong here

    UNION-based SQL injection is not tied to any specific database engine. The UNION operator is part of standard SQL and is implemented across MySQL, Oracle, Microsoft SQL Server, PostgreSQL, SQLite, and others. While each DBMS has its own syntax for additional features (e.g., information schema queries), the core UNION operation works identically in all of them. Therefore, assuming the database must be MySQL is a false prerequisite.

  • ✗

    The application must use GET parameters

    Why it's wrong here

    The injection point can be located in any HTTP request component—GET parameters, POST data, cookies, or custom headers—and the HTTP method itself does not affect how UNION injection behaves. What matters is that user-controlled input is concatenated into a SQL query without proper sanitization. A GET parameter is simply one common vector, not a requirement. UNION injection can just as easily be performed through a POST body or a cookie value.

  • ✗

    The application must display error messages

    Why it's wrong here

    UNION injection extracts data by including a second SELECT query whose results are appended to the original query's result set. This technique does not rely on the application displaying database error messages; in fact, it usually requires the application to return the combined result rows normally. Error messages are only necessary for error-based injection, which is a different approach. Column count and data type matching are what enable successful UNION injection, independent of error visibility.

  • ✓

    The number of columns in both queries must match

    Why this is correct

    A UNION statement in SQL combines the result sets of two or more SELECT queries, and a strict rule is that all queries must have the same number of columns. If the column counts differ, the database engine raises an error and the entire query fails, so the injected SELECT must exactly match the original query's column count. Attackers typically determine the correct number by using ORDER BY clauses or incrementally adding NULL columns until the UNION succeeds. This column-matching requirement is the fundamental constraint that must be satisfied for UNION injection to work.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.