nerdexam
CompTIA

PT0-003 · Question #83

As part of a security audit, a penetration tester finds an internal application that accepts unexpected user inputs, leading to the execution of arbitrary commands. Which of the following techniques…

The correct answer is B. SQL injection. SQL injection (SQLi) is a technique that allows attackers to manipulate SQL queries to execute arbitrary commands on a database. It is one of the most common and effective methods for accessing sensitive data in internal applications that accept unexpected user inputs…

Submitted by akirajp· Mar 6, 2026Attacks and Exploits

Question

As part of a security audit, a penetration tester finds an internal application that accepts unexpected user inputs, leading to the execution of arbitrary commands. Which of the following techniques would the penetration tester most likely use to access the sensitive data?

Options

  • ALogic bomb
  • BSQL injection
  • CBrute-force attack
  • DCross-site scripting

How the community answered

(53 responses)
  • A
    9% (5)
  • B
    85% (45)
  • C
    4% (2)
  • D
    2% (1)

Explanation

SQL injection (SQLi) is a technique that allows attackers to manipulate SQL queries to execute arbitrary commands on a database. It is one of the most common and effective methods for accessing sensitive data in internal applications that accept unexpected user inputs. Arbitrary Command Execution: The question specifies that the internal application accepts unexpected user inputs leading to arbitrary command execution. SQL injection fits this description as it exploits vulnerabilities in the application's input handling to execute unintended SQL commands on the database. Data Access: SQL injection can be used to extract sensitive data from the database, modify or delete records, and perform administrative operations on the database server. This makes it a powerful technique for accessing sensitive information. Common Vulnerability: SQL injection is a well-known and frequently exploited vulnerability in web applications, making it a likely technique that a penetration tester would use to exploit input handling issues in an internal application.

Topics

#SQL injection#web application exploits#data access

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice