EC-Council
EC0-350 · Question #420
A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection…
The correct answer is B. Single quote. See the full explanation below for the reasoning.
Question
A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection is possible, what is the first character that the tester should use to attempt breaking a valid SQL request?
Options
- ASemicolon
- BSingle quote
- CExclamation mark
- DDouble quote
How the community answered
(22 responses)- A5% (1)
- B73% (16)
- C14% (3)
- D9% (2)
Community Discussion
No community discussion yet for this question.