200-201 Network Intrusion Analysis Practice Question
An analyst is investigating a suspected SQL injection attack captured in a PCAP. The analyst needs to identify TWO indicators in the HTTP traffic that would confirm a SQL injection attempt. Which two indicators should the analyst look for? (Choose two.)
⚠ Common exam trap
The trap here is focusing on generic web attack signs like redirects or directory listings, which are not specific to SQL injection, instead of the SQL syntax and error messages that directly indicate database query manipulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unexpected database error messages in HTTP responses
SQL injection attempts are characterized by the injection of SQL syntax into user inputs, often visible as keywords like UNION or OR 1=1 in HTTP requests. Additionally, when the injected query causes a database error, the error message may be returned in the HTTP response, providing confirmation of the attempt. These two indicators together strongly suggest a SQL injection attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unexpected database error messages in HTTP responses
Why this is correct
When SQL injection is attempted, malformed queries can cause the database to return error messages. These errors, such as syntax errors or unclosed quotation marks, often appear in HTTP responses and reveal that the input affected the SQL query, confirming an injection attempt.
- ✗
HTTP response containing a large number of directory listings
Why it's wrong here
Directory listings are unrelated to SQL injection. They typically indicate misconfigured web servers exposing file structures. SQL injection targets database queries, not directory indexing, so this is not a reliable indicator of a SQL injection attempt.
- ✓
Presence of SQL keywords such as UNION, SELECT, or OR 1=1 in URL parameters or POST data
Why this is correct
SQL injection often involves injecting SQL keywords and syntax into input fields to manipulate database queries. Observing terms like UNION SELECT or OR 1=1 in HTTP requests strongly suggests an attempt to alter the intended SQL query, making this a key indicator of SQL injection.
- ✗
Multiple HTTP 302 redirects to an external domain
Why it's wrong here
Redirects to external domains may indicate other attacks like open redirect or phishing, but they are not specific to SQL injection. SQL injection manipulates database queries, and while it could lead to data exfiltration, redirects alone are not a direct indicator of the injection attempt itself.
- ✗
Presence of encrypted payloads using TLS 1.3
Why it's wrong here
Encrypted payloads using TLS 1.3 indicate secure communication, which would prevent inspection of the HTTP content. Since SQL injection indicators are typically found in plaintext HTTP requests and responses, encryption would hide them. This is not an indicator of SQL injection but rather a barrier to analysis.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.