Courseiva
Exploitation Fundamentals →mediumMultiple Choice

GPEN Exploitation Fundamentals Practice Question

During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?

⚠ Common exam trap

The trap here is assuming any error message indicates a specific vulnerability without considering the content of the error.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

Verbose error messages that include database queries and stack traces are a hallmark of SQL injection. They occur when user input is not properly sanitized, allowing attackers to manipulate SQL statements and trigger errors that reveal backend details. This information can be used to further exploit the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site request forgery (CSRF)

    Why it's wrong here

    CSRF tricks a user into performing unintended actions but does not typically generate verbose server errors with database queries. It exploits the user's session, not the application's input handling. The error details provided are characteristic of injection flaws, not CSRF.

  • ✗

    Remote file inclusion (RFI)

    Why it's wrong here

    RFI allows an attacker to include external files, often leading to code execution. It may produce errors if the included file is missing or malformed, but these errors are usually file-related, not database query stack traces. The specific mention of a database query makes RFI unlikely.

  • ✓

    SQL injection

    Why this is correct

    A verbose error with a database query and stack trace strongly indicates SQL injection. When user input is improperly sanitized, it can alter SQL queries, and errors often reveal database structure. This is a classic sign of SQLi, especially when the error includes SQL syntax details.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    XSS typically results in JavaScript execution in the victim's browser, not server-side errors with database queries. While XSS can sometimes cause client-side errors, it does not produce stack traces or SQL query details on the server. The presence of database query information points away from XSS.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.