Courseiva

CEH Web Application and Injection Attacks Practice Question

A penetration tester uses SQLMap with the following command: sqlmap -u 'http://target.com/page.php?id=1' --batch --dbs. Which database enumeration technique is SQLMap using by default?

⚠ Common exam trap

The trap is assuming SQLMap defaults to blind or time-based injection because those are 'safer' — in reality SQLMap prefers in-band (union/error) extraction and only falls back when necessary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In-band SQL injection

SQLMap's default enumeration technique is in-band (union/error-based) SQL injection, which extracts data through the same channel as the request — typically via UNION SELECT or error messages reflected in the HTTP response. With --dbs and no technique flag, SQLMap first attempts in-band methods before falling back to blind or time-based if those fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Out-of-band SQL injection

    Why it's wrong here

    Out-of-band (OOB) SQL injection techniques are not SQLMap's default because they rely on the database server's ability to initiate external network connections, such as DNS lookups or HTTP requests. This capability is often restricted in secure production environments, making OOB methods less universally reliable as a primary testing approach. SQLMap will only attempt OOB methods if explicitly configured or if other, more common in-band and blind techniques fail to yield results.

  • ✗

    Blind SQL injection

    Why it's wrong here

    Blind SQL injection techniques are employed when the application does not directly display database errors or query results to the attacker, making direct data retrieval impossible. SQLMap, by default, prioritizes faster in-band methods like UNION-based or error-based injections for data extraction. Blind techniques, which infer information bit by bit through boolean conditions or time delays, are significantly slower and are only utilized by SQLMap as fallback mechanisms when in-band methods are not viable.

  • ✗

    Time-based SQL injection

    Why it's wrong here

    Time-based SQL injection is a specific type of blind technique where information is inferred based on observable time delays in the server's response to injected queries. This method is inherently slow and inefficient, as each character or condition often requires a distinct, measurable delay to be introduced and observed. SQLMap will only resort to time-based methods if faster in-band (UNION, error) and other blind (boolean-based) techniques prove unsuccessful, positioning it as a last-resort option rather than a default.

  • ✓

    In-band SQL injection

    Why this is correct

    In-band SQL injection is SQLMap's default and preferred method because it allows the attacker to retrieve data directly through the same communication channel used for the original query. This category includes UNION-based attacks, which append a malicious SELECT statement to the original query to return additional data, and error-based attacks, which force the database to return error messages containing query results. These methods are generally the fastest and most efficient for data extraction when applicable, providing immediate feedback.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.