Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

Which SQL injection technique involves injecting a query that causes a delay in response, allowing the attacker to infer information based on response time?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Blind time-based SQL injection

Blind time-based SQL injection uses delays (e.g., WAITFOR DELAY) to infer true/false conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Error-based SQL injection

    Why it's wrong here

    Error-based SQL injection exploits verbose database error messages to reveal schema details, table names, or data directly within the HTTP response. The attacker intentionally triggers a SQL error and reads the error text, so it is a content-based side channel rather than a timing-based one. Because the technique relies on error output, not on injecting a query that causes a deliberate time delay, it does not match the time-based description in the question.

  • ✗

    UNION-based SQL injection

    Why it's wrong here

    UNION-based SQL injection uses the UNION operator to append a malicious query's results to the legitimate query's result set, allowing data to be returned directly in the application's response. This is a non-blind technique because the extracted data is immediately visible in the HTML or API response, with no need to infer anything from response timing. Since it does not involve injecting a query that introduces a measurable time delay, it is not the correct choice.

  • ✗

    Boolean-blind SQL injection

    Why it's wrong here

    Boolean-blind SQL injection sends conditional payloads that produce different response content based on whether a statement evaluates to true or false, and the attacker observes those subtle content differences (e.g., page length, HTTP status). It is a blind technique, but the signal used is the boolean response difference, not a deliberate database delay. Therefore, it does not rely on injecting a query that causes a time-based wait, making it incorrect for this question.

  • ✓

    Blind time-based SQL injection

    Why this is correct

    Blind time-based SQL injection infers information by injecting a query that forces the database to sleep for a set interval only when a certain condition is true, then measuring the response time. For example, in MySQL an attacker can append 'AND SLEEP(5)' to make the query pause 5 seconds if the condition holds, allowing them to extract data character by character. This technique directly matches the description of injecting a query that leverages a temporal delay to infer database contents, so it is the correct answer.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.