Question 1,054 of 1,013
SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst is reviewing web server logs from an e-commerce application. The logs show repeated requests containing URLs with appended strings such as: `' OR '1'='1' --` and `'; DROP TABLE Users; --`. The application returned HTTP 200 responses with unexpected data in several instances. Which type of attack is most likely being attempted?
⚠ Common exam trap
Many exam-takers confuse SQL injection with command injection because both use special characters like `'` and `;`, but command injection requires OS command separators and system commands, whereas SQL injection uses database-specific syntax and keywords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
The repeated requests contain classic SQL injection payloads, such as `' OR '1'='1' --` (used to bypass authentication or extract data) and `'; DROP TABLE Users; --` (used to delete database tables). The HTTP 200 responses with unexpected data confirm that the application is vulnerable to SQL injection, as the injected SQL code is being executed against the backend database. This attack targets the SQL database layer, not LDAP directories or operating system commands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SQL injection
Why this is correct
Correct. The log entries show SQL syntax such as `OR '1'='1'` and `DROP TABLE`, which are classic indicators of SQL injection attempts. This attack exploits improper input sanitization to manipulate database queries. These payloads are appended to SQL statements executed by the web application's backend database, allowing an attacker to bypass authentication or alter data.
- ✗
LDAP injection
Why it's wrong here
LDAP injection exploits vulnerabilities in applications that build LDAP filters from user input without proper sanitization, using constructs like `(&(uid=user)(userPassword=pass))` or wildcard `*` to bypass authentication. The observed payloads (`OR '1'='1'`, `DROP TABLE`) are structured for SQL's WHERE-clause logic, not for LDAP filter syntax, which relies on parentheses, ampersands, and pipe characters (e.g., `(|(cn=...)(uid=...))`). Hence, the attack targets a SQL backend, not an LDAP directory.
When this WOULD be correct
An LDAP injection question would involve an application that authenticates users against an LDAP directory, with logs showing payloads like `*)(uid=*))(|(uid=*` or `admin*` in login fields, causing unauthorized access or data exposure.
- ✗
Command injection
Why it's wrong here
Command injection is an attack where an attacker manipulates user-supplied input to execute arbitrary operating system commands on the host server by injecting shell metacharacters such as `;`, `|`, `&&`, or backticks. The log entries show SQL-specific syntax, not these command separators or OS command names (e.g., `cat`, `ls`, `whoami`). Therefore, this activity is not indicative of command injection.
When this WOULD be correct
Command injection would be correct if the logs showed URL parameters with system commands, such as '; ls -la' or '| dir', and the application returned command output in the HTTP response, indicating the server executed the commands.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
Cross-site scripting (XSS) occurs when an attacker injects malicious client-side scripts, such as JavaScript, into web pages that are then executed in the browsers of other users. The observed log entries contain SQL keywords and operators like `OR '1'='1'` and `DROP TABLE`, rather than script tags, event handlers, or payloads like `<script>alert(1)</script>`, which would be expected for XSS. Thus, the attack pattern does not match XSS.
When this WOULD be correct
A security analyst finds that a web application reflects user input in HTTP responses without sanitization, and a proof-of-concept payload like <script>alert('XSS')</script> executes in a browser. The question would specify that the attack targets other users via stored or reflected scripts.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓SQL injectionCorrect answer▾
Why this is correct
Correct. The log entries show SQL syntax such as `OR '1'='1'` and `DROP TABLE`, which are classic indicators of SQL injection attempts. This attack exploits improper input sanitization to manipulate database queries. These payloads are appended to SQL statements executed by the web application's backend database, allowing an attacker to bypass authentication or alter data.
✗LDAP injectionWrong answer — click to see why▾
Why this is wrong here
The logs show SQL syntax like `' OR '1'='1' --` and `DROP TABLE Users`, which are classic SQL injection payloads, not LDAP injection. LDAP injection uses LDAP query syntax, not SQL.
★ When this WOULD be the correct answer
An LDAP injection question would involve an application that authenticates users against an LDAP directory, with logs showing payloads like `*)(uid=*))(|(uid=*` or `admin*` in login fields, causing unauthorized access or data exposure.
Why candidates choose this
Candidates may confuse injection attacks, thinking any injection that manipulates a query is similar, or they may not distinguish between SQL and LDAP syntax.
✗Command injectionWrong answer — click to see why▾
Why this is wrong here
The logs show SQL syntax patterns like ' OR '1'='1' and DROP TABLE, which are classic SQL injection attempts. Command injection typically involves system commands (e.g., ; ls -la) and would not produce SQL-like strings.
★ When this WOULD be the correct answer
Command injection would be correct if the logs showed URL parameters with system commands, such as '; ls -la' or '| dir', and the application returned command output in the HTTP response, indicating the server executed the commands.
Why candidates choose this
Candidates may confuse injection types, thinking any injected string is a command, or they may not recognize the specific SQL syntax patterns, leading them to choose a broader injection category.
✗Cross-site scripting (XSS)Wrong answer — click to see why▾
Why this is wrong here
The logs show SQL syntax (' OR '1'='1' --, DROP TABLE) and HTTP 200 responses with unexpected data, indicating database manipulation, not client-side script execution. XSS involves injecting scripts into web pages viewed by other users, not direct database queries.
★ When this WOULD be the correct answer
A security analyst finds that a web application reflects user input in HTTP responses without sanitization, and a proof-of-concept payload like <script>alert('XSS')</script> executes in a browser. The question would specify that the attack targets other users via stored or reflected scripts.
Why candidates choose this
Candidates may confuse injection attacks or think that any malicious input in web requests is XSS, especially when the response contains unexpected data, without recognizing the SQL-specific syntax and database commands.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.