Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 4Objective 2

Web Application Attacks and SQL Injection ECSS Practice Questions (Page 8)

Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.

53questions here
11free pages
9concepts

Questions 36–40

  1. 36application · medium

    A penetration tester is testing a web application that does not display database errors or query results. The tester suspects SQL injection and wants to confirm it. Which of the following techniques is the most appropriate?

    Select an answer first
  2. 37expert · hard

    A development team is remediating SQL injection vulnerabilities. The application is a legacy system that uses dynamic SQL in many places. The team has a tight deadline and limited budget. They must choose a mitigation strategy. Which of the following is the most effective strategy given the constraints?

    Select an answer first
  3. 38application · medium

    During a web application test, a penetration tester injects a payload into a search parameter. The application does not display any database error or the query result, but the response time increases significantly when the tester submits ' AND (SELECT COUNT(*) FROM users) > 1000 -- . Which type of SQL injection is the tester most likely exploiting?

    Select an answer first
  4. 39application · medium

    A developer is fixing a SQL injection vulnerability in a PHP application. The current code uses mysql_query() with string concatenation. Which of the following is the most secure replacement?

    Select an answer first
  5. 40expert · hard

    A penetration tester is conducting a web application assessment for a client. The client has a strict policy: no automated scanning tools may be used, and all testing must be manual. The application is a large e-commerce platform with hundreds of input parameters. The tester has limited time. Which of the following is the most effective approach to maximize coverage while complying with the policy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.