Courseiva
Attacks and Exploits →mediumMultiple Select

PT0-002 Attacks and Exploits Practice Question

During a web application penetration test, a tester identifies a SQL injection vulnerability. Which TWO techniques could be used to extract data from the database? (Select TWO.)

⚠ Common exam trap

The trap is that the question says 'SQL injection' but lists non-SQLi techniques (command injection, XXE, XSS) as distractors — candidates who do not carefully map each option to the SQLi family may select an unrelated vulnerability class.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blind time-based SQL injection

Blind time-based SQL injection (C) is correct because when the application returns no visible query output or error messages, the tester can inject conditional statements (e.g., WAITFOR DELAY in MSSQL or SLEEP() in MySQL) and infer data by measuring response delays. UNION-based SQL injection (E) is correct because it appends a crafted UNION SELECT statement to the original query, allowing the attacker to retrieve data from other tables or columns directly in the application's response when the column count and data types match. Command injection (A) targets OS command execution, not SQL query manipulation, so it does not extract database data. XXE injection (B) exploits XML external entity parsing to read files or perform SSRF, which is unrelated to SQL injection. Reflected XSS (D) is a client-side scripting attack that executes JavaScript in a victim's browser and cannot query a database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Command injection

    Why it's wrong here

    Command injection exploits unsanitised shell calls to execute OS commands; it does not extract database contents through a SQL injection flaw. It tempts testers because both are injection classes, but command injection targets the host shell, whereas SQL injection requires UNION-based or blind Boolean/time techniques to read data.

  • ✗

    XXE injection

    Why it's wrong here

    XXE exploits XML parsers to read files or trigger server-side requests; it does not interact with SQL statements or result sets. It is tempting because both are injection flaws in web applications, and XXE suits scenarios where the target parses attacker-supplied XML, but database extraction needs SQL-specific payloads.

  • ✓

    Blind time-based SQL injection

    Why this is correct

    Time-based blind injection embeds conditional delays, such as database sleep functions, into the query. The tester infers each bit of data from whether the response is delayed, extracting content even when no output or error is returned, satisfying the requirement despite absent in-band feedback.

  • ✗

    Reflected XSS

    Why it's wrong here

    Reflected XSS executes script in a victim's browser via unsanitised output; it cannot query a database or return rows. It is tempting because both flaws stem from unvalidated input, and XSS is often chained after SQL injection for session theft, but extraction requires SQL-aware techniques such as UNION-based or blind queries.

  • ✓

    UNION-based SQL injection

    Why this is correct

    UNION-based injection appends a crafted SELECT to the original query, merging attacker-chosen columns into the result set. Because the application returns those rows directly, the tester reads extracted database content in-band, satisfying the requirement to extract data through the vulnerable query's own output.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.