Courseiva

200-201 Network Intrusion Analysis Practice Question

An analyst is investigating a suspected SQL injection attack captured in a PCAP. The analyst needs to identify TWO indicators in the HTTP traffic that would confirm a SQL injection attempt. Which two indicators should the analyst look for? (Choose two.)

⚠ Common exam trap

The trap here is focusing on generic web attack signs like redirects or directory listings, which are not specific to SQL injection, instead of the SQL syntax and error messages that directly indicate database query manipulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unexpected database error messages in HTTP responses

SQL injection attempts are characterized by the injection of SQL syntax into user inputs, often visible as keywords like UNION or OR 1=1 in HTTP requests. Additionally, when the injected query causes a database error, the error message may be returned in the HTTP response, providing confirmation of the attempt. These two indicators together strongly suggest a SQL injection attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Unexpected database error messages in HTTP responses

    Why this is correct

    When SQL injection is attempted, malformed queries can cause the database to return error messages. These errors, such as syntax errors or unclosed quotation marks, often appear in HTTP responses and reveal that the input affected the SQL query, confirming an injection attempt.

  • ✗

    HTTP response containing a large number of directory listings

    Why it's wrong here

    Directory listings are unrelated to SQL injection. They typically indicate misconfigured web servers exposing file structures. SQL injection targets database queries, not directory indexing, so this is not a reliable indicator of a SQL injection attempt.

  • ✓

    Presence of SQL keywords such as UNION, SELECT, or OR 1=1 in URL parameters or POST data

    Why this is correct

    SQL injection often involves injecting SQL keywords and syntax into input fields to manipulate database queries. Observing terms like UNION SELECT or OR 1=1 in HTTP requests strongly suggests an attempt to alter the intended SQL query, making this a key indicator of SQL injection.

  • ✗

    Multiple HTTP 302 redirects to an external domain

    Why it's wrong here

    Redirects to external domains may indicate other attacks like open redirect or phishing, but they are not specific to SQL injection. SQL injection manipulates database queries, and while it could lead to data exfiltration, redirects alone are not a direct indicator of the injection attempt itself.

  • ✗

    Presence of encrypted payloads using TLS 1.3

    Why it's wrong here

    Encrypted payloads using TLS 1.3 indicate secure communication, which would prevent inspection of the HTTP content. Since SQL injection indicators are typically found in plaintext HTTP requests and responses, encryption would hide them. This is not an indicator of SQL injection but rather a barrier to analysis.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.