hardMultiple Select
PT0-002 Practice Question: During a penetration test, the tester discovers a…
During a penetration test, the tester discovers a critical SQL injection vulnerability. The client cannot deploy the full fix (parameterized queries) immediately due to legacy code. Which THREE actions should the tester recommend as compensating controls? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict the database account used by the application to least privilege
Compensating controls reduce risk while the full fix is pending. WAF rules, input validation, and restricted DB privileges are appropriate. Disabling error messages is not a direct compensating control, and patching the DBMS may not address the injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable detailed error messages to prevent information disclosure
Why it's wrong here
Disabling detailed error messages only masks the visible evidence of a database error; it does not alter the vulnerable SQL query execution path. Attackers can still exploit the injection using blind SQL injection techniques, such as time-based or boolean-based payloads, which rely on response timing or content differences rather than error text, so the vulnerability remains fully exploitable and the underlying code defect is untouched.
- ✓
Restrict the database account used by the application to least privilege
Why this is correct
Restricting the database account to least privilege ensures that even when SQL injection succeeds, the attacker's actions are limited to the permissions granted to that account, such as SELECT on specific tables. Without this control, a privileged account (e.g., sa or a database owner) could be used to read sensitive data, write files, execute stored procedures, or escalate to operating system access, turning a single injection point into a full database compromise.
- ✗
Patch the database management system to the latest version
Why it's wrong here
Patching the database management system addresses known vendor-side vulnerabilities (e.g., buffer overflows or privilege escalation flaws in the DB software itself), but the injection vulnerability originates from the application's insecure construction of dynamic SQL queries. The DBMS executes the malformed query exactly as supplied; a fully patched database will still process malicious input if the application concatenates it into SQL, so this action does not remediate the identified flaw.
- ✓
Implement a web application firewall (WAF) rule to block SQL injection patterns
Why this is correct
A web application firewall rule can temporarily block obvious attack signatures, such as ' OR 1=1 --, by matching request patterns at the network edge, but it does not modify the application's code or underlying SQL generation logic. Attackers can bypass many WAF rules using encoding, case variation, comments, or alternative syntax, and the WAF may also produce false positives; therefore, it is a compensating control, not a permanent fix.
- ✓
Apply input validation and sanitization on the affected parameters
Why this is correct
Applying input validation and sanitization on the affected parameters mitigates SQL injection by rejecting or neutralizing characters and sequences that could alter query structure, but the stronger and more reliable remediation is parameterized queries/prepared statements. Validation alone can be bypassed if not comprehensive, so it should be layered with parameterized queries and least privilege access to reduce the attack surface while preserving legitimate input.
Go deeper
Related to this question
Learn chapter
IDOR and Broken Access Control
Key term
Compensating control
A compensating control is a security measure implemented to reduce risk when a primary control cannot be used or is insufficient.
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.