
EC-CouncilEthical Hacking Essentials
Domain 6Objective 3
SQL Injection Attacks and Countermeasures EHE Practice Questions (Page 9)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
43questions here
9free pages
7concepts
Questions 41–43
- 41
A company runs a public-facing web application that connects to a backend database. After a security audit, the company wants to implement multiple layers of defense to reduce the risk of SQL injection. The application code is legacy and cannot be rewritten immediately. Which combination of controls should the company implement first to provide the most immediate protection?
Select an answer first - 42
Which of the following is an indicator that a web application might be vulnerable to SQL injection?
Select an answer first - 43
A security tester is testing a search feature that returns results only if the query matches an exact product name. The tester submits a single quote and receives a database error, but the error message is not displayed to the user. The tester wants to extract data from the database. Which technique is most appropriate in this situation?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.