exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 412 discussion

Actual exam question from CompTIA's PT0-002
Question #: 412
Topic #: 1
[All PT0-002 Questions]

During an assessment of a web application, a penetration tester would like to test the application for blind SQL injection. Which of the following techniques should the penetration tester perform next?

  • A. 1' ORDER BY 1--+
  • B. '; IF (1=1) WAITFOR DELAY '0:0:10'--
  • C. xyz' AND '1' = '1
  • D. xyz' AND (SELECT CASE WHEN (1=1) THEN 1/0 ELSE 'a' END)='a)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alex818119
4 days, 5 hours ago
Selected Answer: B
Bing AI says the answer is B: When it comes to testing for blind SQL injection, a common method involves using time-based techniques to infer the results of queries. This is because the application may not return visible error messages or results directly to the tester. The most suitable choice for a time-based blind SQL injection technique would be: B. '; IF (1=1) WAITFOR DELAY '0:0:10'-- This payload uses the WAITFOR DELAY command, which causes the database to pause for 10 seconds if the condition (1=1) is true. If the application becomes unresponsive for 10 seconds, it indicates that the SQL injection was successful.
upvoted 1 times
...
Learner213
5 days, 11 hours ago
Selected Answer: D
The test answer is D
upvoted 1 times
...
zemijan
3 weeks ago
Selected Answer: B
B. '; IF (1=1) WAITFOR DELAY '0:0:10'--
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago