GCIH Web App Injection Attacks Practice Question
When evaluating potential SQL injection in an application, what is the most significant indicator that an application is vulnerable?
⚠ Common exam trap
Candidates often look for 'lack of error handling' or 'verbose logs'. These are indicators of existing vulnerabilities, but direct string concatenation is the actual root cause of SQL injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User input is directly concatenated into a query string.
The most definitive indicator is the presence of dynamic SQL construction using unsanitized user input. When developers concatenate strings to build queries, the database cannot distinguish between data and command intent. Identifying code patterns where user parameters are directly appended to a SQL string is a critical step in security assessments. This practice allows attackers to manipulate the query structure, leading to unauthorized data exposure, bypasses, or administrative actions within the database management system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application uses a relational database management system.
Why it's wrong here
Relational databases themselves are not inherently vulnerable. The vulnerability resides in how the application constructs queries before sending them to the database. Using a relational database is a standard design choice and provides no indication of security quality or susceptibility to SQL injection without reviewing the code.
- ✓
User input is directly concatenated into a query string.
Why this is correct
String concatenation allows attackers to inject SQL syntax directly into the final command sent to the database. By using quotes and operators, an attacker can escape the data field and alter the query logic. This is the root cause of most SQL injection vulnerabilities in legacy and poorly written applications.
- ✗
The database contains sensitive user data.
Why it's wrong here
The existence of sensitive data is a risk factor for the impact of an exploit, but it is not an indicator of the vulnerability itself. An application can have highly sensitive data and be perfectly secure against SQL injection if it uses properly parameterized queries or safe database abstraction layers.
- ✗
The application is written in an interpreted language.
Why it's wrong here
The programming language choice is irrelevant to SQL injection risk. Both compiled and interpreted languages are susceptible to injection if they interact with databases improperly. The issue is about input handling and query building practices, which are independent of the underlying runtime environment or language characteristics used by the developer.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.