200-201 Network Intrusion Analysis Practice Question
A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?
⚠ Common exam trap
It's easy for candidates to confuse SQL injection with XSS — both inject code into input fields, but SQLi targets the database with SQL syntax while XSS targets the browser with script tags; candidates who see '<script>' often reflexively pick it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GET /products?id=1 UNION SELECT * FROM users
The UNION SELECT payload is the classic SQL injection signature: it appends a second SELECT statement to the original query, allowing the attacker to retrieve data from other tables such as 'users'. The presence of SQL keywords (UNION, SELECT, FROM) inside a URL parameter that should only contain a numeric ID is a strong indicator of SQLi. This pattern targets the backend database directly, unlike script tags which target the browser.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GET /login?user=admin&pass=password123
Why it's wrong here
Submitting credentials in a query string is poor practice, but admin and password123 are literal values, not SQL syntax, so no injection occurs. SQL injection requires metacharacters that break out of the query, such as ' OR '1'='1. This pattern indicates cleartext credential transmission over GET, a separate finding.
- ✗
GET /search?q=<script>alert('XSS')</script>
Why it's wrong here
The payload is a reflected cross-site scripting probe, not SQL injection: script tags execute in a victim's browser rather than altering a database query. SQL injection needs characters such as a single quote, UNION SELECT or OR 1=1 in a parameter. This pattern is the correct indicator when investigating XSS alerts.
- ✓
GET /products?id=1 UNION SELECT * FROM users
Why this is correct
The UNION SELECT payload is injected directly into the id parameter, attempting to append rows from the users table to the query result. This satisfies the SQL injection indicator, unlike plain numeric values or encoded characters that carry no SQL syntax.
- ✗
GET /index.html HTTP/1.1
Why it's wrong here
A plain GET for a static HTML page carries no parameters, so there is no input vector for injected SQL. SQL injection requires user-supplied data reaching a query, typically via query strings, form fields or cookies. This request is the baseline benign traffic an analyst would exclude when filtering for injection attempts.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.