CAS-004 Security Engineering Practice Question
A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for known attack patterns. The administrator wants to ensure that the NIDS can detect a specific SQL injection attempt that uses a particular string. Which Snort rule action and option combination will BEST accomplish this?
⚠ Common exam trap
Test-takers frequently confuse detection with prevention, or assuming that HTTPS traffic can be inspected without decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
alert tcp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
The goal is to detect a SQL injection attempt containing a specific string. Snort rules with the alert action and a content match on TCP port 80 are appropriate for unencrypted HTTP traffic. Using drop would block traffic, which is not required. UDP or port 443 would not match typical SQL injection traffic. Thus, the rule with alert, TCP, port 80, and content match is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
alert udp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
Why it's wrong here
This rule monitors UDP traffic on port 80, but HTTP typically uses TCP. SQL injection attacks are usually delivered over TCP port 80 or 443. Therefore, this rule would miss the attack because it is looking at the wrong protocol, making it ineffective for the stated scenario.
- ✓
alert tcp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
Why this is correct
This rule triggers an alert when the string '1=1' is found in TCP traffic destined for port 80. The content option performs a simple pattern match, which is effective for detecting known SQL injection strings. The alert action logs the event, allowing the administrator to be notified of potential attacks.
- ✗
drop tcp any any -> any 80 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
Why it's wrong here
The drop action not only alerts but also blocks the packet. However, the requirement is to detect, not block. Using drop could disrupt legitimate traffic if false positives occur. For a NIDS, the alert action is more appropriate as it focuses on monitoring and detection without interfering with traffic.
- ✗
alert tcp any any -> any 443 (msg:"SQL Injection"; content:"1=1"; sid:100001;)
Why it's wrong here
This rule inspects TCP traffic on port 443, which is used for HTTPS. While SQL injection can occur over HTTPS, the traffic is encrypted, so the content match would fail unless TLS inspection is performed. Without decryption, the NIDS cannot see the payload, so this rule would not detect the attack.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.