nerdexam
EC-Council

EC0-350 · Question #420

A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection…

The correct answer is B. Single quote. See the full explanation below for the reasoning.

Question

A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection is possible, what is the first character that the tester should use to attempt breaking a valid SQL request?

Options

  • ASemicolon
  • BSingle quote
  • CExclamation mark
  • DDouble quote

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    73% (16)
  • C
    14% (3)
  • D
    9% (2)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice