Courseiva

200-201 Network Intrusion Analysis Practice Question

An intrusion detection system alerts on HTTP traffic containing the string 'UNION SELECT' in the URI parameter. This is most indicative of what type of attack?

⚠ Common exam trap

Cisco often tests the distinction between injection types by using specific payload strings; the trap here is confusing SQL injection with command injection because both involve 'injection', but the 'UNION SELECT' syntax is unique to SQL and not used in command injection or other attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

The alert detects the string 'UNION SELECT' in a URI parameter, which is a classic SQL injection payload used to combine results from multiple database queries. This indicates an attacker is attempting to manipulate SQL queries by injecting malicious SQL code through user input, a hallmark of SQL injection attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SQL injection

    Why this is correct

    The string UNION SELECT combines result sets from separate queries, a hallmark of SQL injection, where attackers append crafted SQL to input fields. Detecting it in a URI parameter indicates an attempt to manipulate the backend database query, satisfying the intrusion signature described.

  • ✗

    Command injection

    Why it's wrong here

    'UNION SELECT' is SQL syntax used to append a second query and extract data, indicating SQL injection rather than command injection, which targets operating-system shell execution. Command injection is tempting because both abuse unsanitised input, but its payloads are shell commands, not SQL keywords.

  • ✗

    Cross-site scripting

    Why it's wrong here

    Cross-site scripting injects script into pages rendered for other users; 'UNION SELECT' is SQL syntax, not markup or JavaScript. XSS is tempting because it also travels in URI parameters, and it would be correct if the payload contained script tags or event handlers aimed at a victim's browser.

  • ✗

    Directory traversal

    Why it's wrong here

    Directory traversal manipulates path sequences such as '../' to reach files outside the web root, so it produces no SQL keywords in the URI. It is tempting because both attacks arrive via crafted HTTP requests, and traversal is the right answer when the payload targets filesystem paths rather than database queries.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.