Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 312-50 Topic 1 Question 76 Discussion

Actual exam question for Eccouncil's 312-50 exam
Question #: 76
Topic #: 1
[All 312-50 Questions]

In an intricate web application architecture using an Oracle database, you, as a security analyst, have identified a potential SQL Injection attack surface. The database consists of 'x' tables, each with y columns. Each table contains z1 records. An attacker, well-versed in SQLi techniques, crafts 'u' SQL payloads, each attempting to extract maximum data from the database. The payloads include UNION SELECT' statements and 'DBMS_XSLPPOCESSOR.READ2CLOB' to read sensitive files. The attacker aims to maximize the total data extracted E=xyz'u'. Assuming 'x=4\ y=2\ and varying z' and 'u\ which situation is likely to result in the highest extracted data volume?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Izetta
2 days ago
Wow, this is a tricky one. I'm not sure if I would have come up with the idea of using the 'DBMS_XSLPPOCESSOR.READ2CLOB' technique to read sensitive files. That's some next-level SQLi stuff.
upvoted 0 times
...
Vallie
4 days ago
Hmm, the correct answer seems to be C, where the attacker targets tables with 600 records using 2 SQL payloads. That's a pretty clever approach to maximize the data extraction.
upvoted 0 times
...
Buck
8 days ago
I'm not sure, but after reading the explanation, I see why option C is the most effective in this scenario.
upvoted 0 times
...
Gary
12 days ago
I agree with Curt. The explanation makes sense, so I would go with option C as well.
upvoted 0 times
...
Curt
16 days ago
I think option C is the best choice because it maximizes the data extraction.
upvoted 0 times
...

Save Cancel