nerdexam
EC-Council

EC0-350 · Question #694

A particular database threat utilizes a SQL injection technique to penetrate a target system. How would an attacker use this technique to compromise a database?

The correct answer is A. An attacker uses poorly designed input validation routines to create or alter SQL commands to gain. See the full explanation below for the reasoning.

Question

A particular database threat utilizes a SQL injection technique to penetrate a target system. How would an attacker use this technique to compromise a database?

Options

  • AAn attacker uses poorly designed input validation routines to create or alter SQL commands to gain
  • BAn attacker submits user input that executes an operating system command to compromise a target
  • CAn attacker gains control of system to flood the target system with requests, preventing legitimate
  • DAn attacker utilizes an incorrect configuration that leads to access with higher-than-expected privilege

How the community answered

(20 responses)
  • A
    85% (17)
  • C
    5% (1)
  • D
    10% (2)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice