Courseiva

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security engineer is reviewing a web application that uses a database. The application constructs SQL queries by concatenating user input directly into the query string. During a penetration test, an attacker enters `' OR '1'='1` in the username field and successfully logs in without valid credentials. Which of the following BEST describes the vulnerability and the most effective mitigation?

⚠ Common exam trap

Watch out — candidates often confuse SQL injection with other injection types like command injection or XSS, and selecting input validation as the primary fix instead of parameterized queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection; mitigate by using parameterized queries (prepared statements).

The payload `' OR '1'='1` is a textbook SQL injection that alters the query's WHERE clause to return true, allowing authentication bypass. The root cause is dynamic SQL construction via string concatenation. Parameterized queries ensure that user input is treated as data, not executable code, effectively neutralizing SQL injection. This is the most robust and recommended mitigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SQL injection; mitigate by using parameterized queries (prepared statements).

    Why this is correct

    The payload `' OR '1'='1` manipulates the SQL query to always evaluate true, bypassing authentication. This is a SQL injection vulnerability caused by concatenating user input into queries. Parameterized queries separate SQL code from data, preventing user input from being interpreted as SQL commands, making them the most effective mitigation for this scenario.

  • ✗

    Cross-site scripting (XSS); mitigate by encoding output.

    Why it's wrong here

    XSS involves injecting client-side scripts into web pages viewed by other users, not manipulating database queries. The payload `' OR '1'='1` is a classic SQL injection attempt that alters the query logic to bypass authentication. Output encoding is an XSS mitigation, not a defense against SQL injection, so this does not address the observed vulnerability.

  • ✗

    Cross-site request forgery (CSRF); mitigate by using anti-CSRF tokens.

    Why it's wrong here

    CSRF tricks an authenticated user's browser into sending unauthorized requests. The attack described involves direct manipulation of a login form to bypass authentication via SQL logic, not forging a request from a victim's browser. Anti-CSRF tokens would not prevent SQL injection because the vulnerability lies in how the query is constructed, not in request origin validation.

  • ✗

    Command injection; mitigate by validating input against a whitelist.

    Why it's wrong here

    Command injection exploits insufficient input validation to execute operating system commands, often using characters like `;` or `|`. The payload here targets SQL syntax with quotes and logical operators, not OS commands. While input validation is good practice, it is not the primary mitigation for SQL injection, which requires parameterized queries.

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.