Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 2

Web Application Attacks and SQL Injection ECSS Practice Questions (Page 7)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

53questions here
11free pages
9concepts

Questions 31–35

  1. 31application · medium

    A web application has a search feature that takes a user-supplied keyword and uses it in a SQL query. The application filters out the word 'SELECT' and 'UNION' from the input. A tester submits the following payload: ' UNION SELECT username, password FROM users -- . The attack fails. Which of the following is the most likely reason?

    Select an answer first
  2. 32foundation · easy

    How does the principle of least privilege help mitigate SQL injection?

    Select an answer first
  3. 33foundation · easy

    In a structured web application penetration test, which phase involves gathering information about the target application and its technologies?

    Select an answer first
  4. 34application · medium

    A developer is writing a search feature for a website. The developer wants to prevent SQL injection. Which coding practice is the most secure for handling user input in a SQL query?

    Select an answer first
  5. 35foundation · easy

    What is the primary purpose of the reporting phase in a web application penetration test?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.