Courseiva
Attacks and Exploits →hardMultiple Choice

PT0-002 Attacks and Exploits Practice Question

During a web application test, a tester discovers a parameter that appears to be vulnerable to SQL injection. They want to extract data from a database using a technique that does not rely on visible output. Which type of SQL injection is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blind time-based SQL injection

Blind SQL injection, specifically time-based, is used when no error or data is returned, allowing inference via time delays.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    UNION-based SQL injection

    Why it's wrong here

    UNION-based SQL injection is technically an in-band technique because it requires the attacker to concatenate a crafted SELECT statement with the original query and have the combined result set rendered directly in the application's response. If the application does not display the query output—for example, because the response is an empty page or a JSON object that discards the data—there is no visible channel to receive the exfiltrated rows. Consequently, this method is ineffective in a blind context where the tester cannot see output, and it also demands exact column matching and compatible data types to succeed.

  • ✓

    Blind time-based SQL injection

    Why this is correct

    Blind time-based SQL injection is the correct answer because it exfiltrates data without requiring any visible output, error message, or outbound network interaction. The attacker injects a conditional expression that triggers a database delay function, such as SLEEP(5) in MySQL, WAITFOR DELAY '0:0:5' in SQL Server, or pg_sleep(5) in PostgreSQL, when the condition evaluates true. By comparing the response time of true versus false conditions, the tester can pose boolean questions (e.g., 'Is the first character of the username A?') and iteratively reconstruct data. This works even when the application always returns the same generic page, making it the most reliable blind technique in a bandwidth-constrained test.

  • ✗

    Out-of-band SQL injection

    Why it's wrong here

    Out-of-band SQL injection relies on the database server initiating a separate network connection, typically DNS or HTTP, to an attacker-controlled listener, using functions like xp_dirtree in SQL Server, UTL_HTTP in Oracle, or load_file in MySQL. It is powerful because it allows data extraction without showing data directly in the response, but it is frequently blocked by outbound firewall rules, DNS filters, or restricted egress traffic. For simple data extraction, time-based blind SQL injection is simpler and more portable, while out-of-band should be reserved for rare cases where timing is unreliable or the database cannot execute delays yet can make external requests.

  • ✗

    Error-based SQL injection

    Why it's wrong here

    Error-based SQL injection leverages database error messages that include fragments of the query or data, for example by triggering a type conversion error, a duplicate key, or using functions like CAST() to cause a visible error that echoes the value. However, this technique is entirely dependent on the application echoing detailed database errors back to the client; many modern frameworks, WAFs, and production environments override verbose database errors with a generic '500 Internal Server Error' or a custom message. In a blind test where even error conditions return identical responses, error-based attacks provide no feedback channel and thus cannot be used to infer information. Therefore, it is a wrong answer for a scenario that only reveals response timing differences.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.