An attacker submits a request containing unexpected characters in an attempt to gain unauthorized access to information within the underlying systems. Which of the following best describes this attack?
Choose an answer
Tap an option to check your answer.
Correct answer: SQL injection.
Why this is the answer
SQL injection is a code injection technique used to attack data-driven applications, where malicious SQL statements are inserted into an entry field for execution (e.g., to dump database contents to the attacker). The attacker exploits vulnerabilities in the application's input validation, allowing them to manipulate or bypass intended queries. Side loading refers to installing software on a device without going through an official app store. Target of evaluation is a term used in security certification to describe the product or system being evaluated. Resource reuse is a secure coding practice where system resources are properly cleared before being reallocated to prevent information leakage. These options do not describe the attack of inserting malicious characters into a request to gain unauthorized access to a database.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed