CompTIA SecurityX (CAS-005)Security OperationsMedium

A security analyst is investigating a critical alert from a web application firewall (WAF) indicating a potential SQL injection attempt against a public-facing web application. The alert shows a suspicious string (' UNION SELECT null, null, @@version -- ') in a URL parameter. Which of the following is the MOST appropriate next step for the analyst to take to contain the immediate threat?

  1. AInitiate a full vulnerability scan of the web application server.
  2. BAnalyze historical logs for previous similar attempts.
  3. CUpdate the web application's database schema.
  4. DBlock the source IP address at the WAF or network firewall.
Show answer & explanation

Correct answer: D. Block the source IP address at the WAF or network firewall.

To contain the immediate threat of an active SQL injection attempt, blocking the source IP address at the WAF or network firewall (B) is the most appropriate and rapid response. This prevents further malicious requests from reaching the application while more detailed investigation and remediation can take place. Other options are important but are either reactive (A), long-term remediation (C), or investigative rather than immediate containment (D).

Why the other options are wrong

  • A. A vulnerability scan is an investigative and preventative measure, not an immediate response to contain an active threat.
  • B. Analyzing historical logs is an investigative step, not an immediate containment action.
  • C. Updating the database schema is a long-term remediation, not an immediate containment of an active attack.

Incident Containment

The phase of incident response focused on limiting the scope and impact of an ongoing security incident. This involves taking immediate actions to stop the attack from spreading or causing further damage, such as isolating systems or blocking malicious traffic.

  • Limits incident scope and impact.
  • Requires immediate, decisive action.
  • Often involves network isolation or blocking.

Memory trick: Contain the threat quickly, don't let it spread.

More Security Operations questions