Courseiva
Question 1,054 of 1,013
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security analyst is reviewing web server logs from an e-commerce application. The logs show repeated requests containing URLs with appended strings such as: `' OR '1'='1' --` and `'; DROP TABLE Users; --`. The application returned HTTP 200 responses with unexpected data in several instances. Which type of attack is most likely being attempted?

⚠ Common exam trap

Many exam-takers confuse SQL injection with command injection because both use special characters like `'` and `;`, but command injection requires OS command separators and system commands, whereas SQL injection uses database-specific syntax and keywords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SQL injection

The repeated requests contain classic SQL injection payloads, such as `' OR '1'='1' --` (used to bypass authentication or extract data) and `'; DROP TABLE Users; --` (used to delete database tables). The HTTP 200 responses with unexpected data confirm that the application is vulnerable to SQL injection, as the injected SQL code is being executed against the backend database. This attack targets the SQL database layer, not LDAP directories or operating system commands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SQL injection

    Why this is correct

    Correct. The log entries show SQL syntax such as `OR '1'='1'` and `DROP TABLE`, which are classic indicators of SQL injection attempts. This attack exploits improper input sanitization to manipulate database queries. These payloads are appended to SQL statements executed by the web application's backend database, allowing an attacker to bypass authentication or alter data.

  • LDAP injection

    Why it's wrong here

    LDAP injection exploits vulnerabilities in applications that build LDAP filters from user input without proper sanitization, using constructs like `(&(uid=user)(userPassword=pass))` or wildcard `*` to bypass authentication. The observed payloads (`OR '1'='1'`, `DROP TABLE`) are structured for SQL's WHERE-clause logic, not for LDAP filter syntax, which relies on parentheses, ampersands, and pipe characters (e.g., `(|(cn=...)(uid=...))`). Hence, the attack targets a SQL backend, not an LDAP directory.

    When this WOULD be correct

    An LDAP injection question would involve an application that authenticates users against an LDAP directory, with logs showing payloads like `*)(uid=*))(|(uid=*` or `admin*` in login fields, causing unauthorized access or data exposure.

  • Command injection

    Why it's wrong here

    Command injection is an attack where an attacker manipulates user-supplied input to execute arbitrary operating system commands on the host server by injecting shell metacharacters such as `;`, `|`, `&&`, or backticks. The log entries show SQL-specific syntax, not these command separators or OS command names (e.g., `cat`, `ls`, `whoami`). Therefore, this activity is not indicative of command injection.

    When this WOULD be correct

    Command injection would be correct if the logs showed URL parameters with system commands, such as '; ls -la' or '| dir', and the application returned command output in the HTTP response, indicating the server executed the commands.

  • Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting (XSS) occurs when an attacker injects malicious client-side scripts, such as JavaScript, into web pages that are then executed in the browsers of other users. The observed log entries contain SQL keywords and operators like `OR '1'='1'` and `DROP TABLE`, rather than script tags, event handlers, or payloads like `<script>alert(1)</script>`, which would be expected for XSS. Thus, the attack pattern does not match XSS.

    When this WOULD be correct

    A security analyst finds that a web application reflects user input in HTTP responses without sanitization, and a proof-of-concept payload like <script>alert('XSS')</script> executes in a browser. The question would specify that the attack targets other users via stored or reflected scripts.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

SQL injectionCorrect answer

Why this is correct

Correct. The log entries show SQL syntax such as `OR '1'='1'` and `DROP TABLE`, which are classic indicators of SQL injection attempts. This attack exploits improper input sanitization to manipulate database queries. These payloads are appended to SQL statements executed by the web application's backend database, allowing an attacker to bypass authentication or alter data.

LDAP injectionWrong answer — click to see why

Why this is wrong here

The logs show SQL syntax like `' OR '1'='1' --` and `DROP TABLE Users`, which are classic SQL injection payloads, not LDAP injection. LDAP injection uses LDAP query syntax, not SQL.

★ When this WOULD be the correct answer

An LDAP injection question would involve an application that authenticates users against an LDAP directory, with logs showing payloads like `*)(uid=*))(|(uid=*` or `admin*` in login fields, causing unauthorized access or data exposure.

Why candidates choose this

Candidates may confuse injection attacks, thinking any injection that manipulates a query is similar, or they may not distinguish between SQL and LDAP syntax.

Command injectionWrong answer — click to see why

Why this is wrong here

The logs show SQL syntax patterns like ' OR '1'='1' and DROP TABLE, which are classic SQL injection attempts. Command injection typically involves system commands (e.g., ; ls -la) and would not produce SQL-like strings.

★ When this WOULD be the correct answer

Command injection would be correct if the logs showed URL parameters with system commands, such as '; ls -la' or '| dir', and the application returned command output in the HTTP response, indicating the server executed the commands.

Why candidates choose this

Candidates may confuse injection types, thinking any injected string is a command, or they may not recognize the specific SQL syntax patterns, leading them to choose a broader injection category.

Cross-site scripting (XSS)Wrong answer — click to see why

Why this is wrong here

The logs show SQL syntax (' OR '1'='1' --, DROP TABLE) and HTTP 200 responses with unexpected data, indicating database manipulation, not client-side script execution. XSS involves injecting scripts into web pages viewed by other users, not direct database queries.

★ When this WOULD be the correct answer

A security analyst finds that a web application reflects user input in HTTP responses without sanitization, and a proof-of-concept payload like <script>alert('XSS')</script> executes in a browser. The question would specify that the attack targets other users via stored or reflected scripts.

Why candidates choose this

Candidates may confuse injection attacks or think that any malicious input in web requests is XSS, especially when the response contains unexpected data, without recognizing the SQL-specific syntax and database commands.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.