Courseiva
Web Application Attacks →mediumMultiple Select

PEN-200 Web Application Attacks Practice Question

You are assessing a web application that uses a relational database backend. During manual testing, you suspect a UNION-based SQL injection vulnerability in a product category parameter. Which two of the following steps are necessary to successfully extract data using a UNION-based SQL injection attack? (Choose two.)

⚠ Common exam trap

The trap here is assuming that additional obfuscation or blind techniques are required for UNION-based injection, when the core requirements are simply column count and data type compatibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine the number of columns returned by the original query.

UNION-based SQL injection requires matching the number of columns in the original query and finding columns that can display string data. These two steps allow the attacker to craft a valid UNION SELECT statement that returns additional data in the application's response. Without knowing the column count, the query will fail; without string-compatible columns, extracted data may not be visible. Other steps like encoding or time delays are not necessary for this attack type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Determine the number of columns returned by the original query.

    Why this is correct

    A UNION-based SQL injection requires that the injected SELECT statement returns the same number of columns as the original query. Without knowing the column count, the database will throw an error and the injection will fail. Testers typically use ORDER BY clauses or UNION SELECT with increasing numbers of NULLs to determine the column count. This step is fundamental to crafting a valid UNION query that retrieves data.

  • ✓

    Identify which columns can display string data from the database.

    Why this is correct

    After determining the column count, the attacker must find which columns are compatible with string data types to display extracted information. Not all columns may accept strings; some might be integers or other types. By injecting UNION SELECT with strings in different positions, the tester can identify visible columns that reflect the data. This step is essential to actually retrieve and view database contents such as table names or user credentials.

  • ✗

    Encode the payload using Base64 to bypass web application firewalls.

    Why it's wrong here

    Base64 encoding is not a standard requirement for UNION-based SQL injection. While encoding can sometimes bypass filters, it is not a necessary step to extract data via UNION. The database must receive the SQL syntax in a form it understands, and Base64 encoding would typically prevent the injection from being interpreted as SQL. In this scenario, the focus is on column count and data type compatibility, not encoding.

  • ✗

    Ensure the database user has file write privileges to create a web shell.

    Why it's wrong here

    File write privileges are not required for UNION-based SQL injection to extract data. The goal is to retrieve information from the database, not to write files to the server. While file write can be an escalation path, it is a separate objective and not part of the UNION data extraction process. In this scenario, the focus is on determining column count and identifying string-compatible columns to display data.

  • ✗

    Use a time delay function to confirm the vulnerability before extracting data.

    Why it's wrong here

    Time delay functions are used in blind SQL injection when no data is returned in the response. In UNION-based injection, the results are directly reflected in the application's output, so time delays are unnecessary. The scenario describes a UNION-based attack, which relies on visible output rather than inference. Therefore, this step is not required and would be more appropriate for blind SQL injection testing.

About these practice questions

This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.