GCIH • Practice Test 16
Free GCIH practice test — 15 questions with explanations. Set 16. No signup required.
During incident response at a financial firm, an analyst discovers that a web application's login form is vulnerable to SQL injection. The backend is Microsoft SQL Server, and the application account has sysadmin rights. The attacker's payloads include ; EXEC xp_cmdshell 'whoami' -- and responses show the web server's service account name. Which immediate containment action best limits further damage while preserving evidence?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.