Courseiva

CEH Network and Web Application Attacks Practice Question

A security analyst is reviewing a web server log and notices a large number of requests with the User-Agent string 'sqlmap/1.5.2#stable'. The requests contain various payloads in the 'id' parameter, such as '1' AND 1=1--' and '1' UNION SELECT null, version()--'. The analyst concludes that an automated SQL injection tool is being used against the application. Which type of attack is being performed?

⚠ Common exam trap

The trap here is assuming any injection with special characters is XSS, but the SQL syntax and tool signature point to SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

The presence of SQL keywords in the payloads and the sqlmap User-Agent clearly indicate an SQL injection attack. The other options represent different injection types that do not match the observed payloads or the tool used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Command injection

    Why it's wrong here

    Command injection involves injecting operating system commands into input fields to execute on the server. The payloads here are SQL statements, not shell commands, and they target the database layer, not the OS. Thus, this is not command injection.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    XSS attacks involve injecting malicious scripts into web pages viewed by other users, typically in parameters that are reflected without sanitization. The payloads here are SQL syntax, not JavaScript, and the goal is to manipulate database queries, not execute scripts in a browser. Therefore, this is not an XSS attack.

  • ✓

    SQL injection

    Why this is correct

    The payloads contain SQL keywords like 'UNION SELECT' and 'AND 1=1', which are classic SQL injection attempts to manipulate database queries. The User-Agent 'sqlmap' indicates an automated tool for SQL injection. This directly matches the scenario, where the attacker is trying to extract or modify database information.

  • ✗

    LDAP injection

    Why it's wrong here

    LDAP injection targets directory services by manipulating LDAP queries, often using characters like parentheses and asterisks. The payloads here use SQL syntax, such as 'UNION SELECT', which is specific to databases. Therefore, this is not LDAP injection.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.