mediumMultiple Choice
PT0-002 Practice Question: During a web application penetration test, a…
During a web application penetration test, a tester identifies a potential SQL injection vulnerability in a search field. The tester wants to extract data from the database without generating error messages that could trigger an alert. Which technique is most appropriate?
⚠ Common exam trap
Watch out — candidates often choose error-based or union-based injection because they are more familiar, failing to recognize that the question explicitly requires avoiding error messages and alerts, which only time-based blind injection achieves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Blind SQL injection (time-based)
Blind SQL injection (time-based) allows data extraction without generating visible error messages or database output. By using conditional time delays (e.g., IF condition THEN WAITFOR DELAY '0:0:5' in SQL Server or SLEEP(5) in MySQL), the tester can infer true/false conditions based on response timing, avoiding any error-based alerts that might be monitored by a WAF or IDS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In-band SQL injection
Why it's wrong here
In-band SQL injection is a broad class where both the crafted query and its results travel over the same communication channel, typically returning data directly in the HTTP response body. Because the attacker immediately receives the database output, security tools and WAFs can easily detect the anomalous request/response pattern, and server logs record the data leak. This makes it the least stealthy approach for penetration testing, as opposed to time-based blind injection, which sends no visible data.
- ✗
Error-based SQL injection
Why it's wrong here
Error-based SQL injection deliberately forces the database to generate a verbose error message, such as a syntax error or type conversion error, that incorporates the desired data into the displayed error string. These errors appear on the application's default error page and often include stack traces or database version details, immediately drawing attention from both automated scanners and human analysts. Additionally, many WAFs have prebuilt signatures for classic error-based payloads, so this method is loudly detectable and not suitable for a covert test.
- ✓
Blind SQL injection (time-based)
Why this is correct
Time-based blind SQL injection is a stealthy technique where the attacker injects a conditional expression that causes the database to pause for a defined period if a certain condition is true, such as using the IF() function or WAITFOR DELAY. The tester infers the answer to a yes/no question about the database by observing the response latency, and no error messages or query results are ever returned to the client. This makes it ideal for blind tests where output is suppressed, though it requires multiple requests and careful handling of network variability.
- ✗
Union-based SQL injection
Why it's wrong here
Union-based SQL injection leverages the UNION operator to combine the original query's result set with a malicious SELECT, allowing the attacker to extract arbitrary data directly into the application's rendered output. To succeed, the attacker must first determine the exact number of columns and compatible data types, typically by incrementally adding NULLs or causing deliberate no-ops. The extracted data is displayed in the page, making the attack visibly obvious to a security analyst, and the trial-and-error process often triggers errors that are logged.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.