Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 5Objective 3

SQL Injection CEH Practice Questions (Page 7)

Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 31–35

  1. 31foundation · easy

    Which of the following is a manual technique to detect a SQL injection vulnerability in a web application's login form?

    Select an answer first
  2. 32foundation · easy

    Which SQL injection technique is commonly used to bypass a login form's authentication by making the WHERE clause always true?

    Select an answer first
  3. 33application · medium · select all that apply

    A penetration tester is evaluating a web application for SQL injection. The tester has identified a parameter that appears to be vulnerable. Which of the following are valid manual techniques to confirm the vulnerability? (Select all that apply.)

    Select an answer first
  4. 34application · medium

    A penetration tester is attempting to bypass authentication on a web application. The login query is: SELECT * FROM users WHERE username = '$user' AND password = '$pass'. The tester wants to log in as the first user in the table without knowing the password. Which payload should the tester use in the username field?

    Select an answer first
  5. 35foundation · easy

    Which of the following is the most effective defense against SQL injection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.