Courseiva

GSEC Incident Handling and Response Practice Question

Exhibit

ERROR: [System.Web.HttpException]: A potentially dangerous Request.Form value was detected from the client (ctl00$MainContent$txtComment='<script>alert(1)</script>').

Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?

⚠ Common exam trap

Candidates frequently confuse the 'Identification' phase with 'Containment'. They assume that because the attack was blocked, the incident is closed, overlooking that identification is necessary to assess the threat actor's intent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cross-Site Scripting; Identification

The exhibit shows a Cross-Site Scripting (XSS) attempt blocked by the application's input validation layer. This should trigger the Identification phase of the incident response lifecycle. Even though the attack was blocked, it indicates an attacker is actively probing the application for vulnerabilities. Early detection allows the team to block the source IP and verify if other, more successful, attempts were made against the infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL Injection; Containment

    Why it's wrong here

    The error log refers to an XSS attempt, not SQL injection, which would involve database queries. Furthermore, the event indicates a blocked attempt, meaning the immediate containment of a breach is not required; rather, the event must be identified and analyzed to determine if further action is needed.

  • ✓

    Cross-Site Scripting; Identification

    Why this is correct

    The log displays an XSS payload injected into a form field, which the framework correctly blocked. This activity represents an active probe by an attacker. It must move to the Identification phase to determine the extent of the scanning or exploitation attempts being conducted against the web application.

  • ✗

    Cross-Site Request Forgery; Eradication

    Why it's wrong here

    This is not a CSRF attack, as the payload is clearly XSS script injection. Eradication is also incorrect because the attack was blocked, and no system infection has occurred. The incident requires identification and analysis, not the removal of a persistent threat or malware from the web servers.

  • ✗

    Buffer Overflow; Preparation

    Why it's wrong here

    This is not a buffer overflow, which involves memory corruption at the process level. Additionally, this event is occurring in real-time and must be handled via the incident response process, not the Preparation phase, which is for pre-incident planning and establishing the security framework before any attacks occur.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.