mediumMultiple Choice
ISC2 CC Practice Question: A security analyst is configuring an intrusion…
A security analyst is configuring an intrusion detection system (IDS) to detect SQL injection attacks. Which method is most effective?
⚠ Common exam trap
The trap is confusing SQL injection detection with other network security monitoring like port scan detection or DNS analysis, which are not directly related to SQL injection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Examine HTTP request parameters for SQL commands
To detect SQL injection attacks, an IDS should examine HTTP request parameters for SQL commands. SQL injection typically involves injecting malicious SQL code into input fields, which then appears in HTTP requests. By analyzing these parameters for patterns like ' OR '1'='1' or UNION SELECT, the IDS can identify and alert on potential attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Analyze DNS query patterns
Why it's wrong here
DNS query analysis inspects domain lookups, not HTTP payloads, so SQL syntax in requests goes unseen; signature or anomaly inspection of application traffic is required. DNS monitoring is tempting because it detects data exfiltration and command-and-control, and it would be correct for those threats rather than injection.
- ✗
Detect port scans from external IPs
Why it's wrong here
Port scans reveal reconnaissance, not the crafted SQL syntax inside application requests, so this signature never matches an injection attempt. It is tempting because scanning often precedes exploitation, making port-scan detection correct for identifying pre-attack reconnaissance rather than the injection itself.
- ✓
Examine HTTP request parameters for SQL commands
Why this is correct
SQL injection payloads travel inside HTTP request parameters, so inspecting those parameters for SQL keywords and syntax detects the attack at the application layer. Signature matching on packet headers or ports alone would miss the injected commands, making parameter inspection the effective method.
- ✗
Monitor bandwidth usage for spikes
Why it's wrong here
Bandwidth spikes indicate volume anomalies such as flooding or exfiltration, not the semantic content of a query, so injection payloads pass unseen. It is tempting because volumetric monitoring suits denial-of-service detection, which is the scenario where this method would be the right choice.
Go deeper
Related to this question
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.