What should an analyst do first after discovering a SQL injection in query.php?
While investigating a possible incident, a security analyst discovers the following: Which of the following should the analyst do first? - 
Community Votes
75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests incident response ordering—validate a suspected SQL injection before containing; the trap is disabling query.php or blocking brute force without confirming compromise.
When an analyst finds a SQL injection attempt in query.php logs, the correct first step in SY0-701 incident response is to check the users table for new accounts. This page establishes why validating the attack's success precedes containment actions like disabling the script or deploying a WAF.
Many candidates choose B and immediately disable query.php, but containment should follow identification; disabling the script first can destroy evidence and does not prove whether the INSERT succeeded.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The log excerpt shows an attempted SQL injection through query.php, including an INSERT INTO users statement that tries to create a temporary account. In CompTIA's incident response doctrine, the identification and analysis phase comes before containment; the analyst must first determine whether the attack succeeded. Checking the users table for new accounts (D) directly validates the scope of the potential compromise and reveals unauthorized access. This evidence then drives appropriate containment, such as disabling query.php or resetting credentials. Therefore D is the correct first action.Why the Other Options Are Wrong
A is wrong because implementing a WAF is a preventive, longer-term control, not the immediate investigative step. B is tempting as containment, but disabling query.php before confirming compromise can destroy volatile evidence and may be premature if the INSERT never executed. C is irrelevant because the logs show SQL injection, not a brute-force attack against temporary users. None of these options address the immediate need to validate whether the incident actually resulted in account creation.Community Comment Notes
As Fourgehan noted, checking the users table gives "immediate insight into whether the incident has led to unauthorized access" before containment. fmeox567 similarly explained that SQL injection can lead to account creation, so D confirms whether the attack succeeded. chasingsummer preferred disabling query.php, but that is a containment action better taken after validation. BevMe interpreted the second log entry as an INSERT INTO users attempt, reinforcing that the analyst must verify the database change first.Exam Strategy
In SY0-701 incident response questions, prioritize the step that validates the incident before containing it. If the scenario shows SQL injection, checking the affected database object (like the users table) is usually the identification step, not disabling the vulnerable script.
Frequently Asked Questions
Why is disabling query.php not the first step after a SQL injection alert?
Disabling the script is a containment action. CompTIA incident response requires identifying whether the attack succeeded first, so you don't destroy evidence or miss unauthorized accounts.
What in the log indicates a SQL injection attempt against query.php?
An INSERT INTO users statement embedded in a web request to query.php indicates an attempt to add unauthorized accounts to the database.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →