GPEN Exploitation Fundamentals Practice Question
You are conducting a penetration test against a web application. During exploitation, you identify a SQL injection vulnerability that allows you to execute arbitrary SQL queries. You want to leverage this to gain remote code execution on the underlying database server. Which TWO of the following techniques are most likely to achieve this goal? (Choose two.)
⚠ Common exam trap
Candidates often confuse data extraction techniques like UNION-based or blind SQL injection with methods that directly execute code, such as writing a web shell or using xp_cmdshell.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploiting the SQL injection to write a web shell to the web server's root directory using INTO OUTFILE.
The two techniques that directly lead to remote code execution from SQL injection are writing a web shell via INTO OUTFILE and using xp_cmdshell on MSSQL. Both require specific privileges and configurations but are proven methods to escalate from SQL injection to full command execution on the server. Other options focus on data extraction or reading files, which do not directly achieve RCE.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Exploiting the SQL injection to write a web shell to the web server's root directory using INTO OUTFILE.
Why this is correct
If the database user has FILE privileges and the web server directory is writable, you can use INTO OUTFILE to write a web shell (e.g., PHP) to a web-accessible location. This directly leads to remote code execution by accessing the shell via a browser. It is a common and effective technique when the database and web server are on the same host.
- ✗
Injecting a stored procedure that uses the LOAD_FILE function to read sensitive files from the server.
Why it's wrong here
LOAD_FILE is used to read files, not execute code. It can be useful for reading configuration files or source code, but it does not provide remote code execution. This technique is for information gathering, not for achieving RCE. It may help in further exploitation but is not a direct method.
- ✗
Performing a blind SQL injection to infer the database schema and then using that information to craft a more targeted attack.
Why it's wrong here
Blind SQL injection is used when the application does not return query results directly. It is a method for data exfiltration, not direct code execution. While the schema information could be useful for further attacks, it does not by itself lead to remote code execution. This option describes a reconnaissance step, not an RCE technique.
- ✗
Using UNION-based SQL injection to extract data from the database and then cracking password hashes offline.
Why it's wrong here
UNION-based injection is excellent for data extraction, but it does not directly lead to remote code execution. Cracking password hashes offline may yield credentials, but that is a separate step and not a direct RCE technique. This method is more about information disclosure than achieving code execution on the server.
- ✓
Using stacked queries to execute operating system commands via xp_cmdshell on a Microsoft SQL Server.
Why this is correct
On Microsoft SQL Server, if stacked queries are supported and the user has sufficient privileges, you can enable and execute xp_cmdshell to run OS commands. This directly achieves remote code execution. It is a well-known technique for escalating from SQL injection to full system compromise on MSSQL.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.