Courseiva

200-201 Network Intrusion Analysis Practice Question

A security analyst is investigating an alert that indicates a potential SQL injection attack. Which of the following HTTP request patterns is most indicative of a SQL injection attempt?

⚠ Common exam trap

It's easy for candidates to confuse SQL injection with XSS — both inject code into input fields, but SQLi targets the database with SQL syntax while XSS targets the browser with script tags; candidates who see '<script>' often reflexively pick it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GET /products?id=1 UNION SELECT * FROM users

The UNION SELECT payload is the classic SQL injection signature: it appends a second SELECT statement to the original query, allowing the attacker to retrieve data from other tables such as 'users'. The presence of SQL keywords (UNION, SELECT, FROM) inside a URL parameter that should only contain a numeric ID is a strong indicator of SQLi. This pattern targets the backend database directly, unlike script tags which target the browser.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GET /login?user=admin&pass=password123

    Why it's wrong here

    Submitting credentials in a query string is poor practice, but admin and password123 are literal values, not SQL syntax, so no injection occurs. SQL injection requires metacharacters that break out of the query, such as ' OR '1'='1. This pattern indicates cleartext credential transmission over GET, a separate finding.

  • ✗

    GET /search?q=<script>alert('XSS')</script>

    Why it's wrong here

    The payload is a reflected cross-site scripting probe, not SQL injection: script tags execute in a victim's browser rather than altering a database query. SQL injection needs characters such as a single quote, UNION SELECT or OR 1=1 in a parameter. This pattern is the correct indicator when investigating XSS alerts.

  • ✓

    GET /products?id=1 UNION SELECT * FROM users

    Why this is correct

    The UNION SELECT payload is injected directly into the id parameter, attempting to append rows from the users table to the query result. This satisfies the SQL injection indicator, unlike plain numeric values or encoded characters that carry no SQL syntax.

  • ✗

    GET /index.html HTTP/1.1

    Why it's wrong here

    A plain GET for a static HTML page carries no parameters, so there is no input vector for injected SQL. SQL injection requires user-supplied data reaching a query, typically via query strings, form fields or cookies. This request is the baseline benign traffic an analyst would exclude when filtering for injection attempts.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.