Answer:
SQL Injection
Explanation:
An SQL injection attack is a malicious activity that takes advantage of poor program design and accesses a database in a means other than was intended.
while:
Denial of service attack(DOS) is a cyber attack on a machine or network resource for a temporary period of time or indefinitely.
Session hijacking is trying to gain unauthorize access to a computer system.
Sniffing is the capturing of data as it is transmitted over a network.
Since roy is to test a database, all other attack aside SQL injection is not appropriate.