EC-Council
EC0-350 · Question #694
A particular database threat utilizes a SQL injection technique to penetrate a target system. How would an attacker use this technique to compromise a database?
The correct answer is A. An attacker uses poorly designed input validation routines to create or alter SQL commands to gain. See the full explanation below for the reasoning.
Question
A particular database threat utilizes a SQL injection technique to penetrate a target system. How would an attacker use this technique to compromise a database?
Options
- AAn attacker uses poorly designed input validation routines to create or alter SQL commands to gain
- BAn attacker submits user input that executes an operating system command to compromise a target
- CAn attacker gains control of system to flood the target system with requests, preventing legitimate
- DAn attacker utilizes an incorrect configuration that leads to access with higher-than-expected privilege
How the community answered
(20 responses)- A85% (17)
- C5% (1)
- D10% (2)
Community Discussion
No community discussion yet for this question.