Investigating a Date-Triggered Database Deletion Script

A company's online shopping website became unusable shortly after midnight on January 30, 2023. When a security analyst reviewed the database server, the analyst noticed the following code used for backing up data: Which of the following should the analyst do next? - image

  1. Check for recently terminated DBAs. Source Reference Answer
  2. Review WAF logs for evidence of command injection.
  3. Scan the database server for malware.
  4. Search the web server for ransomware notes.

Community Votes

A
54%
B
46%

54% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to differentiate between external exploitation vectors and internal sabotage, recognizing that dormant, conditionally-executed code in scheduled jobs strongly indicates an insider with prior administrative access.

This scenario examines incident response when discovering a logic bomb embedded in automated backup routines. Community consensus emphasizes investigating insider threats, particularly terminated privileged users, as the most probable source of such targeted, scheduled sabotage.

Candidates frequently select reviewing WAF logs for command injection, misinterpreting the embedded SQL as an external attack rather than recognizing the deliberate, pre-planted nature of a logic bomb.

Community Discussion (11 comments)

Cee007 👍 9 Selected: A
A. Check for recently terminated DBAs. The code indicates that the database was intentionally dropped based on a specific date, which suggests that someone with access and knowledge of the database setup (such as a database administrator) may have executed or scheduled this command. Checking for recently terminated DBAs could help identify if an insider threat or an ex-employee had a role in this incident.
myazureexams 👍 5 Selected: B
The answer is B. Based on the provided scenario, the security analyst should prioritize reviewing Web Application Firewall (WAF) logs for evidence of command injection. The unusual database command suggests an unauthorized change, possibly through an injection attack. Checking for recently terminated DBAs is less relevant in this situation.
bfb88b4 👍 1 Selected: B
The answer is B and I believe that should be the first step. A check with copilot says Based on the situation described, where malicious code appears to have intentionally dropped the database on a specific date, the most appropriate next step for the security analyst would likely be B. Review WAF logs for evidence of command injection. Here’s why: Investigating the WAF logs might lead to valuable insights into how this malicious action was triggered
Commando9800 👍 1 Selected: B
The best action is to check WAF logs first to determine its not an external command injection attack. After that A is the go-to
CSue 👍 2 Selected: A
Why not B? Review WAF logs for evidence of command injection: This is unnecessary in this case because the malicious code is already in the database, indicating insider action rather than external exploitation via command injection.
dbrowndiver 👍 1 Selected: A
The given SQL code (DROP DATABASE) appears to be intentionally destructive, as it specifies a condition (IF DATE() = "01/30/2023") to delete the primary database on a specific date. Such activity is often indicative of an insider threat, particularly by someone who had privileged access to the database, such as a Database Administrator (DBA). The first step is to investigate whether a disgruntled employee or recently terminated DBA inserted this malicious code into the backup process.
bluekb 👍 2 Selected: A
Answer should be A. The analyst found a logic bomb in the database backup code most likely in a job running on the sever on schedule. Most likely this job was created by the DBA. SQL injection code typically uses special command characters to comment out the normally run code.
laternak26 👍 1 Selected: B
he WAF logs could provide valuable information on malicious requests or attempts to exploit such vulnerabilities, especially command injection.
PAWarriors 👍 2 Selected: B
B. Review WAF logs for evidence of command injection. The code provided (DROP DATABASE WebShopOnline) suggests that the database was deliberately dropped on a specific date (January 30, 2023). This could potentially be the result of a command injection attack, where an attacker inserts malicious code to manipulate or destroy the database.
17f9ef0 👍 1 Selected: B
Answer is B
a4e15bd 👍 1 Selected: B
While insider threats are always a possibility, the structure of the code suggest an automated or external trigger, rather than an action by a disgruntled employee. A terminate DBA would likely have direct access to drop the database rather than making such as time specific command. Attackers use SQL injection to execute commands like DROP Database remotely through vulnerable interfaces. So B. Reviewing the WAF logs for evidence of command injection makes the correct answer.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Identifying the Attack Vector

The provided SQL snippet demonstrates a logic bomb: a piece of code designed to execute a destructive action (dropping a database) only when a specific condition is met (a particular date). Unlike active exploits, logic bombs lie dormant until triggered, requiring careful planning and legitimate system access to embed.

Why Option A is Correct

Option A correctly directs the analyst to investigate insider threats. Placing a date-specific deletion script into a routine backup job requires deep knowledge of the database architecture, backup schedules, and administrative privileges. As noted by multiple candidates in the community discussion, this pattern strongly suggests a disgruntled or terminated employee who had authorized access before leaving the organization. Checking recently terminated DBAs is the most direct and logical initial step to identify the perpetrator and assess their activity timeline.

Why Other Options Are Incorrect

  • Option B (WAF Logs): Web Application Firewalls monitor inbound HTTP traffic for vulnerabilities like SQL injection or command injection. However, the malicious code here is not being injected via a user-facing web form at runtime; it is hardcoded into a scheduled maintenance job. As several commenters pointed out, WAF logs would not reveal how the script was originally planted or executed internally.
  • Option C (Malware Scan): While malware can cause data loss, the highly specific, conditional SQL syntax points to human-authored sabotage rather than random malicious software behavior. Forensic prioritization should focus on the most probable cause first.
  • Option D (Ransomware Notes): Ransomware variants encrypt files and demand payment for decryption keys. This scenario describes outright database destruction, which aligns with sabotage or data wiping, not extortion.

Incident Response Best Practice

When uncovering malicious scripts in automated processes, always prioritize privilege and access reviews. Determining who created or modified the job, when it was deployed, and whether any high-risk personnel recently lost access will quickly narrow the investigation scope.

Official Reference

Exam Strategy

When analyzing malicious code snippets in exam scenarios, examine the execution context and trigger mechanism. If the code is dormant, scheduled, or conditionally executed based on dates/system states, immediately suspect insider activity or pre-planted sabotage rather than real-time external exploitation. Match the technical artifact to the corresponding investigation path.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide