Courseiva
Web Application Attacks →mediumMultiple Select

PEN-200 Web Application Attacks Practice Question

You are assessing a login form and suspect a blind SQL injection vulnerability. The application does not return database errors, but the response time varies significantly based on the input. Which TWO of the following techniques would be most effective to confirm this vulnerability?

⚠ Common exam trap

Test-takers often look only for error-based payloads, forgetting that blind SQL injection requires alternative side-channel techniques like time delays or boolean conditions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Injecting 'SLEEP(5)' or equivalent wait commands.

Blind SQL injection relies on inferring data through side channels like time delays or Boolean logic. Time-based payloads force the database to pause, while Boolean-based payloads cause the page content to change based on true/false conditions. These methods are essential when direct data output is suppressed, allowing an attacker to reconstruct the database contents systematically through repeated, measured queries to the back-end server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Injecting 'SLEEP(5)' or equivalent wait commands.

    Why this is correct

    Time-based payloads force the database to execute a delay before responding. If the server response is delayed by exactly the specified duration, it confirms that the injected command was successfully executed by the backend engine, providing a reliable indicator for confirming blind SQL injection vulnerabilities during testing.

  • ✗

    Reviewing the server's source code files.

    Why it's wrong here

    Reviewing source code is a white-box assessment technique, not a blind SQL injection exploitation method. In a blind testing scenario, you operate as a black-box tester without access to internal logic. You must rely on external observation of application behavior to infer the presence of a flaw.

  • ✓

    Injecting payloads that alter Boolean response conditions.

    Why this is correct

    Boolean-based techniques involve sending queries that result in a 'true' or 'false' condition. By observing whether the application returns the standard page or a modified version, you can deduce data bit-by-bit. This is a standard approach for blind injection when time-based methods are unreliable or restricted.

  • ✗

    Forcing the application to display verbose error messages.

    Why it's wrong here

    Verbose error messages are characteristic of error-based SQL injection, not blind SQL injection. Blind injection is specifically defined by the absence of visible database errors. If an application provides error feedback, it is no longer considered a blind injection scenario, and different exploitation vectors would be prioritized.

  • ✗

    Attempting to perform a Cross-Site Request Forgery.

    Why it's wrong here

    Cross-Site Request Forgery involves tricking a user into performing unwanted actions on an application where they are authenticated. This is a client-side vulnerability and has no functional relation to SQL injection, which targets the backend database layer to manipulate query logic and extract data from the server.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.