GCIH Network and Log Investigations Practice Question
An incident handler is examining a web server's access logs after a suspected SQL injection attempt. The log shows a request with a long URL containing multiple single quotes and 'UNION SELECT' statements. Which log field is most critical to correlate this request with other events to determine if the attack succeeded?
⚠ Common exam trap
The trap here is assuming that the HTTP status code alone can indicate a successful attack, but many SQL injection attempts return 200 OK even when they fail, and status codes are not unique enough for correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The source IP address and timestamp
Correlating events across disparate logs requires a common identifier such as source IP and timestamp. These fields allow the incident handler to pivot from the web server log to database logs, firewall logs, or IDS alerts to see if the SQL injection resulted in data extraction, error messages, or additional requests. Other fields like User-Agent or status code may provide context but lack the uniqueness needed for reliable correlation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The HTTP status code
Why it's wrong here
The HTTP status code indicates the outcome of the request (e.g., 200 OK, 500 Internal Server Error), which can suggest whether the attack caused an error, but it does not uniquely identify the request to correlate with other logs. Multiple requests can share the same status code, making it insufficient for precise event correlation.
- ✓
The source IP address and timestamp
Why this is correct
The source IP address and timestamp provide a unique combination that can be used to correlate the web request with other log sources, such as database logs, firewall logs, or authentication logs. This allows the incident handler to trace the attacker's actions across multiple systems and determine if the SQL injection led to further compromise.
- ✗
The User-Agent string
Why it's wrong here
The User-Agent string identifies the client software and version, which can indicate if the request came from a known attack tool like sqlmap, but it does not help correlate the request with server-side events such as database errors or subsequent file access. It is useful for attribution but not for linking the request to other actions on the server.
- ✗
The requested URL path
Why it's wrong here
The requested URL path shows which resource was targeted but does not include the full query string in some logging configurations, and it lacks temporal or source information. Without the source IP and timestamp, it is difficult to link this specific request to other events, especially if the same path is accessed by multiple users.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.