Courseiva

GCIH Web App Injection Attacks Practice Question

When evaluating potential SQL injection in an application, what is the most significant indicator that an application is vulnerable?

⚠ Common exam trap

Candidates often look for 'lack of error handling' or 'verbose logs'. These are indicators of existing vulnerabilities, but direct string concatenation is the actual root cause of SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User input is directly concatenated into a query string.

The most definitive indicator is the presence of dynamic SQL construction using unsanitized user input. When developers concatenate strings to build queries, the database cannot distinguish between data and command intent. Identifying code patterns where user parameters are directly appended to a SQL string is a critical step in security assessments. This practice allows attackers to manipulate the query structure, leading to unauthorized data exposure, bypasses, or administrative actions within the database management system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application uses a relational database management system.

    Why it's wrong here

    Relational databases themselves are not inherently vulnerable. The vulnerability resides in how the application constructs queries before sending them to the database. Using a relational database is a standard design choice and provides no indication of security quality or susceptibility to SQL injection without reviewing the code.

  • ✓

    User input is directly concatenated into a query string.

    Why this is correct

    String concatenation allows attackers to inject SQL syntax directly into the final command sent to the database. By using quotes and operators, an attacker can escape the data field and alter the query logic. This is the root cause of most SQL injection vulnerabilities in legacy and poorly written applications.

  • ✗

    The database contains sensitive user data.

    Why it's wrong here

    The existence of sensitive data is a risk factor for the impact of an exploit, but it is not an indicator of the vulnerability itself. An application can have highly sensitive data and be perfectly secure against SQL injection if it uses properly parameterized queries or safe database abstraction layers.

  • ✗

    The application is written in an interpreted language.

    Why it's wrong here

    The programming language choice is irrelevant to SQL injection risk. Both compiled and interpreted languages are susceptible to injection if they interact with databases improperly. The issue is about input handling and query building practices, which are independent of the underlying runtime environment or language characteristics used by the developer.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.