nerdexam
EC-Council

412-79V9 · Question #70

412-79V9 Question #70: Real Exam Question with Answer & Explanation

Sign in or unlock 412-79V9 to reveal the answer and full explanation for question #70. The question stem and answer options stay visible for context.

Question

SQL injection attack consists of insertion or "injection" of either a partial or complete SQL query via the data input or transmitted from the client (browser) to the web application. A successful SQL injection attack can: I)Read sensitive data from the database II)Modify database data (insert/update/delete) III)Execute administration operations on the database (such as shutdown the DBMS) IV)Recover the content of a given file existing on the DBMS file system or write files into the file system V)Issue commands to the operating system. In which of the following tests is the source code of the application tested in a non-runtime environment to detect the SQL injection vulnerabilities?

Options

  • AAutomated Testing
  • BFunction Testing
  • CDynamic Testing
  • DStatic Testing

Unlock 412-79V9 to see the answer

You've previewed enough free 412-79V9 questions. Unlock 412-79V9 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full 412-79V9 Practice