What should an analyst do first after discovering a SQL injection in query.php?

Given an incident, apply appropriate incident response activities. Given a scenario, analyze indicators of malicious activity.
Answer Correct answer: D — Check the users table for new accounts first to confirm whether the SQL injection via query.php succeeded before containing the incident.

While investigating a possible incident, a security analyst discovers the following: Which of the following should the analyst do first? - image

  1. Implement a WAF.
  2. Disable the query.php script.
  3. Block brute-force attempts on temporary users.
  4. Check the users table for new accounts. Correct Answer

Community Votes

D
75%
B
25%

75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests incident response ordering—validate a suspected SQL injection before containing; the trap is disabling query.php or blocking brute force without confirming compromise.

When an analyst finds a SQL injection attempt in query.php logs, the correct first step in SY0-701 incident response is to check the users table for new accounts. This page establishes why validating the attack's success precedes containment actions like disabling the script or deploying a WAF.

Many candidates choose B and immediately disable query.php, but containment should follow identification; disabling the script first can destroy evidence and does not prove whether the INSERT succeeded.

Community Discussion (4 comments)

Fourgehan 👍 3 Selected: D
D. Check the users table for new accounts. This step will provide immediate insight into whether the incident has led to unauthorized access or account creation, allowing for a more informed response to the situation
fmeox567 👍 2 Selected: D
D. Check the users table for new accounts. Here's why: SQL injection can lead to unauthorized database access and modifications, such as creating new user accounts. By checking the users table for any suspicious or unauthorized accounts, the analyst can quickly identify if the attack succeeded and take immediate action to remove or disable those accounts.
BevMe 👍 1 Selected: D
The second log entry shows a potential SQL injection attack where the request contains the string: sql Copy code 123 INSERT INTO users VALUES ('temp', 'pass123')# This suggests that the attacker is attempting to insert a new record into the "users" table by exploiting a vulnerability in the query.php script. The first step the security analyst should take is to check the users table for any new accounts that might have been created during the attack.
chasingsummer 👍 2 Selected: B
Best immediate action: disable the query.php script

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The log excerpt shows an attempted SQL injection through query.php, including an INSERT INTO users statement that tries to create a temporary account. In CompTIA's incident response doctrine, the identification and analysis phase comes before containment; the analyst must first determine whether the attack succeeded. Checking the users table for new accounts (D) directly validates the scope of the potential compromise and reveals unauthorized access. This evidence then drives appropriate containment, such as disabling query.php or resetting credentials. Therefore D is the correct first action.

Why the Other Options Are Wrong

A is wrong because implementing a WAF is a preventive, longer-term control, not the immediate investigative step. B is tempting as containment, but disabling query.php before confirming compromise can destroy volatile evidence and may be premature if the INSERT never executed. C is irrelevant because the logs show SQL injection, not a brute-force attack against temporary users. None of these options address the immediate need to validate whether the incident actually resulted in account creation.

Community Comment Notes

As Fourgehan noted, checking the users table gives "immediate insight into whether the incident has led to unauthorized access" before containment. fmeox567 similarly explained that SQL injection can lead to account creation, so D confirms whether the attack succeeded. chasingsummer preferred disabling query.php, but that is a containment action better taken after validation. BevMe interpreted the second log entry as an INSERT INTO users attempt, reinforcing that the analyst must verify the database change first.

Exam Strategy

In SY0-701 incident response questions, prioritize the step that validates the incident before containing it. If the scenario shows SQL injection, checking the affected database object (like the users table) is usually the identification step, not disabling the vulnerable script.

Frequently Asked Questions

Why is disabling query.php not the first step after a SQL injection alert?

Disabling the script is a containment action. CompTIA incident response requires identifying whether the attack succeeded first, so you don't destroy evidence or miss unauthorized accounts.

What in the log indicates a SQL injection attempt against query.php?

An INSERT INTO users statement embedded in a web request to query.php indicates an attempt to add unauthorized accounts to the database.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide