PEN-200 Web Application Attacks Practice Question
You are testing a web application that uses a MySQL database. You suspect a UNION-based SQL injection in the 'id' parameter of a product page. The page displays product names and descriptions. Which two steps are necessary to successfully extract data using a UNION attack? (Choose two.)
⚠ Common exam trap
The trap here is thinking that time-based injection is always needed to confirm SQL injection, when UNION attacks rely on direct output and can be tested by observing changes in the page.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Determine the number of columns in the original query using ORDER BY or UNION SELECT.
A successful UNION-based SQL injection requires matching the number of columns in the original query and identifying which columns are reflected in the response. These steps allow the attacker to craft a UNION SELECT that returns data in visible fields. Other techniques like time-based injection or file privileges are unrelated to UNION extraction and are not necessary for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Determine the number of columns in the original query using ORDER BY or UNION SELECT.
Why this is correct
To perform a UNION attack, the number of columns in the injected query must match the original query. Using ORDER BY with increasing column numbers or injecting UNION SELECT with NULLs helps determine the column count. Without this, the database returns an error, and the injection fails. This step is fundamental to crafting a valid UNION statement that aligns with the original query's structure.
- ✗
Ensure the database user has FILE privileges to read data from the filesystem.
Why it's wrong here
FILE privileges are needed for reading or writing files via SQL injection, but UNION-based extraction retrieves data from database tables, not the filesystem. The attack only requires SELECT privileges on the target tables. Requiring FILE privileges is a misconception; it is not a prerequisite for UNION attacks and would not help in extracting data from the database.
- ✓
Identify which columns are displayed on the page by injecting unique strings into each column.
Why this is correct
After determining the column count, you must find which columns are reflected in the response. Injecting distinct strings (e.g., 'a', 'b') into each column via UNION SELECT reveals which columns are rendered. Only those columns can be used to extract data. This step ensures you retrieve meaningful output rather than blind injection, making the attack efficient and verifiable.
- ✗
Use a time-based injection to confirm the vulnerability before attempting UNION.
Why it's wrong here
Time-based injection is an alternative technique for blind SQL injection, but it is not required for UNION-based attacks. UNION attacks rely on visible output, so you can directly test for them by injecting a UNION SELECT and observing changes. Using time-based methods adds unnecessary complexity and may not be needed if the page reflects query results. This step is not necessary for UNION exploitation.
- ✗
Encode the payload using base64 to bypass web application firewalls.
Why it's wrong here
Base64 encoding is not a standard method for SQL injection bypass; it would alter the payload so the database does not interpret it as SQL. WAF bypass often involves obfuscation, comments, or alternate encodings, but base64 is not directly usable. This step is irrelevant to UNION-based extraction and would likely break the injection rather than help.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.