
EC-CouncilWeb Application Hacking and Security
Domain 2Objective 1
Advanced SQL Injection (SQLi) WAHS Practice Questions (Page 5)
Part of the Injection Attacks domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
9concepts
Questions 21–25
- 21
A tester is assessing a web application that suppresses all output and does not show timing differences due to a very fast database. However, the database server can make DNS requests. Which technique should the tester use to extract data?
Select an answer first - 22
A security consultant is testing a web application that is heavily firewalled and returns no output or timing differences for any SQL injection attempts. The consultant has control of a domain name and can monitor DNS queries. Which technique should the consultant use to exfiltrate data from the database?
Select an answer first - 23
Which of the following best describes the impact of a successful SQL injection attack?
Select an answer first - 24
A tester is assessing a web application that uses a MySQL database. The application filters out single quotes and the words 'AND', 'OR', 'SELECT', and 'UNION'. The tester suspects time-based blind SQLi. Which payload is most likely to work?
Select an answer first - 25
In boolean-based blind SQL injection, how does an attacker infer information from the database?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.