Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 5Objective 3

SQL Injection CEH Practice Questions (Page 6)

Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 26–30

  1. 26foundation · easy

    Which type of SQL injection relies on the same communication channel to both inject the malicious SQL and receive the results?

    Select an answer first
  2. 27application · medium

    A penetration tester is exploiting a SQL injection vulnerability in a search feature. The tester wants to extract data from a different table in the same database. The original query is: SELECT title, description FROM products WHERE category = '$cat'. Which technique should the tester use to retrieve data from the 'users' table?

    Select an answer first
  3. 28application · medium

    A security tester is evaluating a web application that displays user profile information. The tester suspects SQL injection in the 'username' parameter. When the tester submits a payload that causes a DNS lookup to an external domain, the tester observes the DNS query in the logs. Which type of SQL injection is this, and what is the primary advantage of this technique?

    Select an answer first
  4. 29application · medium

    A security analyst is testing a web application's search feature. The analyst submits a single quote (') and receives a database error. The analyst then submits ' AND 1=1 -- and the page returns results, but ' AND 1=2 -- returns no results. Which type of SQL injection is this, and what is the most appropriate next step to confirm the vulnerability?

    Select an answer first
  5. 30application · medium

    A penetration tester is assessing a legacy web application that uses string concatenation to build SQL queries. The tester wants to confirm a suspected SQL injection vulnerability in the login form with minimal noise and without causing database errors that could alert the security team. Which approach should the tester use first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.