Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy

A security operations center (SOC) analyst is reviewing alerts from the SIEM. One alert indicates 'Multiple failed attempts to access a critical database using SQL queries containing 'UNION SELECT' and 'pg_sleep()'. The source IP is from an external, untrusted network. Which vulnerability is the attacker most likely attempting to exploit?

  1. ASQL Injection
  2. BBuffer Overflow
  3. CCross-Site Request Forgery (CSRF)
  4. DDirectory Traversal
Show answer & explanation

Correct answer: A. SQL Injection

The presence of 'UNION SELECT' and 'pg_sleep()' within SQL queries is a classic signature of SQL injection attempts. 'UNION SELECT' is used to extract data, and 'pg_sleep()' is often used for time-based blind SQL injection.

Why the other options are wrong

  • B. Buffer overflow exploits memory management vulnerabilities, not SQL query logic.
  • C. CSRF exploits trust in a user's browser, not through direct SQL query manipulation.
  • D. Directory traversal attempts to access files outside the intended directory, not through SQL queries.

SQL Injection Signatures

SQL injection signatures are specific keywords, functions, or patterns found within attacker-crafted SQL queries that indicate an attempt to exploit database vulnerabilities.

  • Common keywords: 'UNION SELECT', 'OR 1=1', 'DROP TABLE'.
  • Functions for enumeration: '@@version', 'user()', 'database()'.
  • Functions for timing attacks: 'SLEEP()', 'pg_sleep()'.
  • Often seen in web application logs targeting input fields.

Memory trick: Web app attacks are like trying to break into a house through its windows, some target specific flaws.

More Security Monitoring questions