PT0-002 Attacks and Exploits Practice Question
During a web application penetration test, a tester identifies a SQL injection vulnerability. Which TWO techniques could be used to extract data from the database? (Select TWO.)
⚠ Common exam trap
The trap is that the question says 'SQL injection' but lists non-SQLi techniques (command injection, XXE, XSS) as distractors — candidates who do not carefully map each option to the SQLi family may select an unrelated vulnerability class.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Blind time-based SQL injection
Blind time-based SQL injection (C) is correct because when the application returns no visible query output or error messages, the tester can inject conditional statements (e.g., WAITFOR DELAY in MSSQL or SLEEP() in MySQL) and infer data by measuring response delays. UNION-based SQL injection (E) is correct because it appends a crafted UNION SELECT statement to the original query, allowing the attacker to retrieve data from other tables or columns directly in the application's response when the column count and data types match. Command injection (A) targets OS command execution, not SQL query manipulation, so it does not extract database data. XXE injection (B) exploits XML external entity parsing to read files or perform SSRF, which is unrelated to SQL injection. Reflected XSS (D) is a client-side scripting attack that executes JavaScript in a victim's browser and cannot query a database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Command injection
Why it's wrong here
Command injection exploits unsanitised shell calls to execute OS commands; it does not extract database contents through a SQL injection flaw. It tempts testers because both are injection classes, but command injection targets the host shell, whereas SQL injection requires UNION-based or blind Boolean/time techniques to read data.
- ✗
XXE injection
Why it's wrong here
XXE exploits XML parsers to read files or trigger server-side requests; it does not interact with SQL statements or result sets. It is tempting because both are injection flaws in web applications, and XXE suits scenarios where the target parses attacker-supplied XML, but database extraction needs SQL-specific payloads.
- ✓
Blind time-based SQL injection
Why this is correct
Time-based blind injection embeds conditional delays, such as database sleep functions, into the query. The tester infers each bit of data from whether the response is delayed, extracting content even when no output or error is returned, satisfying the requirement despite absent in-band feedback.
- ✗
Reflected XSS
Why it's wrong here
Reflected XSS executes script in a victim's browser via unsanitised output; it cannot query a database or return rows. It is tempting because both flaws stem from unvalidated input, and XSS is often chained after SQL injection for session theft, but extraction requires SQL-aware techniques such as UNION-based or blind queries.
- ✓
UNION-based SQL injection
Why this is correct
UNION-based injection appends a crafted SELECT to the original query, merging attacker-chosen columns into the result set. Because the application returns those rows directly, the tester reads extracted database content in-band, satisfying the requirement to extract data through the vulnerable query's own output.
Go deeper
Related to this question
Learn chapter
Physical Security Testing Techniques
Key term
XSS
Cross-Site Scripting (XSS) is a security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.