Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 2Objective 1

Advanced SQL Injection (SQLi) WAHS Practice Questions (Page 9)

Part of the Injection Attacks domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
9concepts

Questions 41–42

  1. 41expert · hard

    A tester is assessing a web application that suppresses all output and timing differences are unreliable due to network jitter. The database is Oracle and has outbound network access. The tester wants to exfiltrate data. Which technique is most appropriate?

    Select an answer first
  2. 42application · medium

    A penetration tester is testing a web application that returns the same HTTP status code and body for all requests, regardless of the query result. The tester has confirmed that SQL injection is possible but cannot observe any output differences. Which technique should the tester use to extract the current database name?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to WAHS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.