Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard
A software development team is performing a code review to identify potential security flaws before deploying a critical update. During the review, a developer discovers that user input is directly concatenated into a database query without proper validation or sanitization. This vulnerability could allow an attacker to execute arbitrary database commands. Which type of attack is possible due to this vulnerability?
- ACross-Site Scripting (XSS)
- BBuffer Overflow
- CDenial of Service (DoS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: D. SQL Injection
SQL Injection occurs when malicious SQL code is inserted into input fields, which is then executed by the database. The scenario describes exactly this vulnerability: user input directly used in a query without sanitization, allowing arbitrary commands.
Why the other options are wrong
- A. XSS involves injecting malicious client-side scripts into web pages viewed by other users, not database queries.
- B. Buffer Overflow involves writing data beyond the allocated buffer size, often leading to code execution, but is a memory corruption vulnerability, not directly related to unsanitized database input.
- C. DoS attacks aim to make a service unavailable, typically by overwhelming it, not by injecting commands into database queries.
SQL Injection
A code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g., to dump database content to the attacker).
- Exploits improper input validation in web applications.
- Allows attackers to manipulate database queries.
- Can lead to data theft, alteration, or complete system compromise.
Memory trick: SQL Injection is like 'talking directly to the database' through a sneaky message.