PT0-002 Attacks and Exploits Practice Question
During a web application test, the tester uses sqlmap and identifies a time-based blind SQL injection. Which technique is sqlmap using to extract data?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Time-based blind SQL injection
Time-based blind SQL injection uses conditional delays to infer the truth of queries based on response time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Error-based SQL injection
Why it's wrong here
Error-based SQL injection is incorrect here because it leverages verbose database error messages to extract or infer data directly in the application's response. For example, MySQL's `extractvalue` or `updatexml` functions can cause a syntax error that echoes the subquery result, while MSSQL's `CONVERT` can cast an integer to expose data in the error text. This technique produces immediate, visible error output rather than relying on measurable delays in response time, so it would not be the correct classification when a timeout or sleep is observed.
- ✗
Boolean-based blind SQL injection
Why it's wrong here
Boolean-based blind SQL injection is wrong for this scenario because it infers data by sending predicates that alter the HTTP response content or status code, such as `AND 1=1` versus `AND 1=2`, then comparing the resulting page markup or 200/404 outcomes. It does not use any database timing primitives like `SLEEP` or `WAITFOR DELAY`; instead, it relies on observable differences in the application's normal versus altered behavior. Since the detection here is predicated on response latency, not response differentials, this option does not fit.
- ✗
UNION-based SQL injection
Why it's wrong here
UNION-based SQL injection is not the correct answer because it is a non-blind technique that appends a `UNION SELECT` statement to the original query, requiring the attacker to match the exact number and data types of the original result set. The injected rows are rendered directly into the HTTP response, allowing immediate retrieval of database content without any timing mechanism. Given that the tester observed a time delay rather than unexpected data appearing in the response, this option is incompatible with the observed behavior.
- ✓
Time-based blind SQL injection
Why this is correct
Time-based blind SQL injection is the correct answer because the tester can extract data by injecting conditional expressions that invoke database delay functions, such as `IF(condition, SLEEP(5), 0)` in MySQL or `WAITFOR DELAY '0:0:5'` in MSSQL, and then measuring the application's response time. Sqlmap automatically generates these payloads and uses a statistical threshold to distinguish between true and false conditions based on elapsed time, making it effective when no error messages or content changes are visible. This aligns perfectly with the scenario where the tester used sqlmap and observed time-based behavior.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.