Courseiva
hardMultiple Select

PT0-002 Practice Question: During a penetration test, the tester discovers a…

During a penetration test, the tester discovers a critical SQL injection vulnerability. The client cannot deploy the full fix (parameterized queries) immediately due to legacy code. Which THREE actions should the tester recommend as compensating controls? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict the database account used by the application to least privilege

Compensating controls reduce risk while the full fix is pending. WAF rules, input validation, and restricted DB privileges are appropriate. Disabling error messages is not a direct compensating control, and patching the DBMS may not address the injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable detailed error messages to prevent information disclosure

    Why it's wrong here

    Disabling detailed error messages only masks the visible evidence of a database error; it does not alter the vulnerable SQL query execution path. Attackers can still exploit the injection using blind SQL injection techniques, such as time-based or boolean-based payloads, which rely on response timing or content differences rather than error text, so the vulnerability remains fully exploitable and the underlying code defect is untouched.

  • ✓

    Restrict the database account used by the application to least privilege

    Why this is correct

    Restricting the database account to least privilege ensures that even when SQL injection succeeds, the attacker's actions are limited to the permissions granted to that account, such as SELECT on specific tables. Without this control, a privileged account (e.g., sa or a database owner) could be used to read sensitive data, write files, execute stored procedures, or escalate to operating system access, turning a single injection point into a full database compromise.

  • ✗

    Patch the database management system to the latest version

    Why it's wrong here

    Patching the database management system addresses known vendor-side vulnerabilities (e.g., buffer overflows or privilege escalation flaws in the DB software itself), but the injection vulnerability originates from the application's insecure construction of dynamic SQL queries. The DBMS executes the malformed query exactly as supplied; a fully patched database will still process malicious input if the application concatenates it into SQL, so this action does not remediate the identified flaw.

  • ✓

    Implement a web application firewall (WAF) rule to block SQL injection patterns

    Why this is correct

    A web application firewall rule can temporarily block obvious attack signatures, such as ' OR 1=1 --, by matching request patterns at the network edge, but it does not modify the application's code or underlying SQL generation logic. Attackers can bypass many WAF rules using encoding, case variation, comments, or alternative syntax, and the WAF may also produce false positives; therefore, it is a compensating control, not a permanent fix.

  • ✓

    Apply input validation and sanitization on the affected parameters

    Why this is correct

    Applying input validation and sanitization on the affected parameters mitigates SQL injection by rejecting or neutralizing characters and sequences that could alter query structure, but the stronger and more reliable remediation is parameterized queries/prepared statements. Validation alone can be bypassed if not comprehensive, so it should be layered with parameterized queries and least privilege access to reduce the attack surface while preserving legitimate input.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.