ALL PASS, NO FAIL!

CEH v13 Module 15: SQL Injection — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 15 of 20

Database attacks: union-based, boolean/time-based blind SQLi, error-based techniques, detection, and prevention. Exam focus: walk union-based, blind, and out-of-band attacks step by step — including what each sqlmap flag does — and know why parameterized queries are the answer to nearly every prevention question in this module.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: The payload ' OR 1=1-- entered on a login form:

Answer: D — The comment (-- ) strips the rest of the query and the tautology OR 1=1 matches every row — classic first-order injection.

Question 2: UNION-based SQL injection requires knowing:

Answer: B — 'ORDER BY 3--' errors when it exceeds the column count — once matched, 'UNION SELECT …' injects attacker data into the visible response.

Question 3: Boolean-based blind SQL injection works by:

Answer: A — ' AND 1=1 vs ' AND 1=2 — identical-looking pages that differ subtly leak one character at a time (or bit by bit).

Question 4: Time-based blind SQL injection detects true conditions via:

Answer: C — When the injected condition is true, the server sleeps — response time becomes the data channel when no visible output exists.

Question 5: Out-of-band SQL injection exfiltrates data using:

Answer: B — Functions like LOAD_FILE() with attacker domains build DNS queries containing stolen data — used when in-band responses are unavailable.

Question 6: Error-based SQL injection is identified by:

Answer: D — Verbose errors (extractvalue/updatexml tricks on MySQL) smuggle query results into exception text — production apps should suppress raw DB errors.

Question 7: Which sqlmap command lists the databases discovered against a target URL?

Answer: A — --dbs enumerates databases; then -D dbname --tables lists tables, -T tbl --dump extracts rows, and --os-shell / --passwords go further.

Question 8: The strongest primary defense against SQL injection is:

Answer: C — Prepared statements make injected SQL inert data; layer on least-privilege DB accounts, WAF rules, and code review as defense-in-depth.

Question 9: On Microsoft SQL Server, which feature can be abused after a successful SQL injection to execute operating-system commands?

Answer: A — xp_cmdshell runs system commands from the DB engine (often disabled by default); LOAD_FILE/INTO OUTFILE are MySQL equivalents.

Question 10: Stacked queries in SQL injection allow an attacker to:

Answer: A — Where the driver permits multiple statements ('; DROP TABLE users--'), injection escalates from data theft to schema destruction — another reason for parameterization and least privilege.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 SQL Injection practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 15 (SQL Injection). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 15 (SQL Injection) cover?

Database attacks: union-based, boolean/time-based blind SQLi, error-based techniques, detection, and prevention. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 15 flashcards at https://cehstudy.com/ceh-v13/module-15/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this SQL Injection quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH SQL Injection flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 15 (SQL Injection). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 15 page at https://cehstudy.com/ceh-v13/module-15/. No account or sign-up required.