CompTIA DataSys+ (DS0-001)Data and Database SecurityEasy

A web application developer suspects that a recent increase in database errors and unexpected query results is due to malicious input. The application uses dynamically generated SQL queries based on user input for search functions. Which vulnerability is MOST likely being exploited?

  1. ASQL injection
  2. BBroken authentication
  3. CCross-site scripting (XSS)
  4. DDenial-of-service (DoS)
Show answer & explanation

Correct answer: A. SQL injection

SQL injection occurs when an attacker inserts malicious SQL code into an input field, which is then executed by the database. Dynamically generated SQL queries based on unsanitized user input are a classic vulnerability for SQL injection, leading to unexpected query results and database errors.

Why the other options are wrong

  • B. Broken authentication issues relate to session management or login bypass, not direct database query manipulation.
  • C. XSS injects client-side scripts, not SQL, and affects users' browsers, not directly the database backend in this manner.
  • D. DoS aims to make a service unavailable, not primarily to manipulate query results or cause specific database errors through input.

SQL Injection

A code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.

  • Exploits vulnerabilities in dynamically generated SQL queries.
  • Can lead to unauthorized data access, modification, or deletion.
  • Prevented by using parameterized queries or prepared statements.

Memory trick: Web apps have many entry points for digital mischief.

More Data and Database Security questions