GPEN Exploitation Fundamentals Practice Question
During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?
⚠ Common exam trap
The trap here is assuming any error message indicates a specific vulnerability without considering the content of the error.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
Verbose error messages that include database queries and stack traces are a hallmark of SQL injection. They occur when user input is not properly sanitized, allowing attackers to manipulate SQL statements and trigger errors that reveal backend details. This information can be used to further exploit the database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site request forgery (CSRF)
Why it's wrong here
CSRF tricks a user into performing unintended actions but does not typically generate verbose server errors with database queries. It exploits the user's session, not the application's input handling. The error details provided are characteristic of injection flaws, not CSRF.
- ✗
Remote file inclusion (RFI)
Why it's wrong here
RFI allows an attacker to include external files, often leading to code execution. It may produce errors if the included file is missing or malformed, but these errors are usually file-related, not database query stack traces. The specific mention of a database query makes RFI unlikely.
- ✓
SQL injection
Why this is correct
A verbose error with a database query and stack trace strongly indicates SQL injection. When user input is improperly sanitized, it can alter SQL queries, and errors often reveal database structure. This is a classic sign of SQLi, especially when the error includes SQL syntax details.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
XSS typically results in JavaScript execution in the victim's browser, not server-side errors with database queries. While XSS can sometimes cause client-side errors, it does not produce stack traces or SQL query details on the server. The presence of database query information points away from XSS.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.