Courseiva
Escalation and Exploitation →mediumMultiple Choice

GPEN Escalation and Exploitation Practice Question

During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?

⚠ Common exam trap

Candidates often look for generic web shell upload methods instead of focusing on native database administrative features specific to Microsoft SQL Server like xp_cmdshell.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stored procedure execution via xp_cmdshell

Database features like 'xp_cmdshell' in Microsoft SQL Server allow for the execution of arbitrary operating system commands from within a SQL query. If the database service account has sufficient privileges, this allows an attacker to pivot from SQL injection to full system command execution. Checking for this feature is a critical step in escalating database access to server-level administrative control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Database backup functionality

    Why it's wrong here

    Backups are useful for exfiltration of data, but they do not provide a direct vector for command execution. While one could theoretically restore a malicious backup to overwrite files, this is not the standard or most efficient method for achieving RCE during an active penetration test engagement.

  • ✓

    Stored procedure execution via xp_cmdshell

    Why this is correct

    xp_cmdshell is a powerful stored procedure in Microsoft SQL Server that spawns a Windows command shell and passes in a command string for execution. It is the primary target for testers attempting to escalate from SQL injection to remote code execution on the underlying database server host.

  • ✗

    Database triggers on update

    Why it's wrong here

    Triggers can be used for persistence or modifying data upon events, but they do not inherently provide the ability to execute OS commands. They run within the database context, meaning they are limited to SQL operations and cannot escape the database engine to interact with the OS.

  • ✗

    Database user enumeration

    Why it's wrong here

    Enumerating database users is a reconnaissance activity that provides information about the environment, but it is not a mechanism for achieving code execution. It helps in understanding the level of access but does not inherently grant the ability to execute arbitrary commands on the host server.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.