Courseiva
Web Application Attacks →easyMultiple Choice

PEN-200 Web Application Attacks Practice Question

While testing a web application, you find that the login form is vulnerable to SQL injection. You input the username 'admin'-- and a blank password. The application logs you in as admin without validating the password. Which type of SQL injection attack is this?

⚠ Common exam trap

The trap here is overcomplicating the scenario and assuming that any SQL injection must involve data extraction, when in fact authentication bypass is a distinct and common goal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authentication bypass via SQL injection

The attack uses a comment sequence (--) to truncate the SQL query, eliminating the password validation. This directly bypasses authentication, granting access as the admin user. Union-based, error-based, and blind SQL injection are different techniques used for data extraction or inference, not for simple authentication bypass. Thus, authentication bypass via SQL injection is the correct answer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Authentication bypass via SQL injection

    Why this is correct

    The payload 'admin'-- comments out the rest of the SQL query, effectively removing the password check. This allows the attacker to log in as admin without knowing the password. This is a classic authentication bypass using SQL injection. It does not require data extraction or error messages, and the result is immediate access, making this the correct categorization.

  • ✗

    Error-based SQL injection

    Why it's wrong here

    Error-based SQL injection relies on database error messages to extract information. Here, the attack does not trigger or rely on errors; it manipulates the query logic to bypass authentication. The application likely returns a successful login without any error, so error-based injection is not applicable. This option misidentifies the technique used.

  • ✗

    Blind SQL injection

    Why it's wrong here

    Blind SQL injection is used when the application does not return query results or errors, requiring inference through boolean or time-based responses. In this case, the attacker directly observes a successful login, so it is not blind. The attack is straightforward and relies on visible outcome, making blind injection an incorrect classification.

  • ✗

    Union-based SQL injection

    Why it's wrong here

    Union-based SQL injection involves using the UNION operator to combine the results of two SELECT queries. In this scenario, the attack does not use UNION; it simply comments out the password check. Union-based attacks are used to extract data from other tables, not to bypass authentication in this manner. Therefore, this is not the correct classification.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.