Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Pre-Final Exam in Computer Security

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

What is SQL Injection (SQLi)?

a)

A method to protect databases from attacks

b)

An injection attack where malicious SQL statements are executed

c)

A method of encrypting database data

2.

Which of the following is NOT a type of SQL Injection?

a)

Error-based SQLi

b)

Blind SQLi

c)

UNION-based SQLi

d)

Deaf SQLi

3.

What does Error-Based SQLi rely on?

a)

Network delay

b)

Error messages from the database

c)

Password brute-forcing

4.

Which SQL operator is used in UNION-based SQLi?

a)

JOIN

b)

UNION

c)

MERGE

5.

What is the purpose of @@version in Error-Based SQLi?

a)

To retrieve column names

b)

To display the current version of the database

c)

To delete tables

6.

What should you do before displaying field values in Error-Based SQLi?

a)

Check column order

b)

Convert table name to hex

c)

Log in as admin

7.

In Blind SQLi, what does the following payload do? AND (length(database())) = 8--+**

a)

Deletes the database

b)

Checks if the database name is 8 characters long

c)

Returns all database names

8.

What is the purpose of ascii(substr(...)) in Blind SQLi?

a)

Measures query length

b)

Extracts characters one by one using ASCII values

c)

Encrypts column names

9.

What is the correct query to extract column names from a table using Blind SQLi?

a)

SELECT * FROM columns;

b)

SELECT column_name FROM table_name;

c)

SELECT ascii(substr((SELECT column_name FROM information_schema.columns WHERE table_name = 'table'),1,1))--+

10.

What does group_concat(column_name) do?

a)

Sums up values in a column

b)

Groups identical columns

c)

Lists all column names in one string