nerdexam
GAQM

CPEH-001 · Question #194

A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection…

The correct answer is B. Single quote. See the full explanation below for the reasoning.

Question

A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection is possible, what is the first character that the tester should use to attempt breaking a valid SQL request?

Options

  • ASemicolon
  • BSingle quote
  • CExclamation mark
  • DDouble quote

How the community answered

(31 responses)
  • A
    16% (5)
  • B
    71% (22)
  • C
    3% (1)
  • D
    10% (3)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice