CompTIA CySA+ (CS0-003)Incident Response and ManagementEasy

A security analyst is reviewing logs from a web server after an alert about unusual activity. The following log snippet is observed: ``` GET /index.php?page=products.php%27%20UNION%20SELECT%20null,database(),null--%20HTTP/1.1 Host: example.com User-Agent: Mozilla/5.0 ``` Which type of attack is indicated by this log entry?

  1. APath Traversal
  2. BSQL Injection (SQLi)
  3. CDistributed Denial of Service (DDoS)
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. SQL Injection (SQLi)

The log entry clearly shows an attempt to inject SQL commands into the `page` parameter. The `UNION SELECT null,database(),null--` payload is a classic SQL injection technique used to extract database information.

Why the other options are wrong

  • A. Path traversal attacks attempt to access restricted directories by manipulating file paths (e.g., `../etc/passwd`), not by injecting SQL keywords.
  • C. DDoS attacks involve overwhelming a system with traffic, which is not reflected in this single log entry.
  • D. XSS typically involves injecting client-side scripts (e.g., JavaScript) into web pages, not SQL commands.

SQL Injection (SQLi)

A code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.

  • Exploits vulnerabilities in database interaction.
  • Can lead to data theft, data manipulation, or system compromise.
  • Often uses keywords like UNION, SELECT, OR, AND, etc.

Memory trick: Log entries reveal the attacker's intent, like a detective reading a criminal's notes.

More Incident Response and Management questions