Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A security analyst is configuring an intrusion…

A security analyst is configuring an intrusion detection system (IDS) to detect SQL injection attacks. Which method is most effective?

⚠ Common exam trap

The trap is confusing SQL injection detection with other network security monitoring like port scan detection or DNS analysis, which are not directly related to SQL injection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Examine HTTP request parameters for SQL commands

To detect SQL injection attacks, an IDS should examine HTTP request parameters for SQL commands. SQL injection typically involves injecting malicious SQL code into input fields, which then appears in HTTP requests. By analyzing these parameters for patterns like ' OR '1'='1' or UNION SELECT, the IDS can identify and alert on potential attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Analyze DNS query patterns

    Why it's wrong here

    DNS query analysis inspects domain lookups, not HTTP payloads, so SQL syntax in requests goes unseen; signature or anomaly inspection of application traffic is required. DNS monitoring is tempting because it detects data exfiltration and command-and-control, and it would be correct for those threats rather than injection.

  • ✗

    Detect port scans from external IPs

    Why it's wrong here

    Port scans reveal reconnaissance, not the crafted SQL syntax inside application requests, so this signature never matches an injection attempt. It is tempting because scanning often precedes exploitation, making port-scan detection correct for identifying pre-attack reconnaissance rather than the injection itself.

  • ✓

    Examine HTTP request parameters for SQL commands

    Why this is correct

    SQL injection payloads travel inside HTTP request parameters, so inspecting those parameters for SQL keywords and syntax detects the attack at the application layer. Signature matching on packet headers or ports alone would miss the injected commands, making parameter inspection the effective method.

  • ✗

    Monitor bandwidth usage for spikes

    Why it's wrong here

    Bandwidth spikes indicate volume anomalies such as flooding or exfiltration, not the semantic content of a query, so injection payloads pass unseen. It is tempting because volumetric monitoring suits denial-of-service detection, which is the scenario where this method would be the right choice.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.