312-50V13 · Question #593
Consider a hypothetical situation where an attacker, known for his proficiency in SQL Injection attacks, is targeting your web server. This adversary meticulously crafts 'q' malicious SQL queries…
The correct answer is A. q=17, T=220: Even though the attacker increases 'q', the total delay ('q*d' = 221 seconds) just. The scenario where 'q=17' and 'd=13' results in a total delay of 221 seconds, which exceeds the threshold 'T=220', will most likely trigger an alert.
Question
Options
- Aq=17, T=220: Even though the attacker increases 'q', the total delay ('q*d' = 221 seconds) just
- Bq=13, T=180: In this case, the total delay caused by the attacker ('q*d' = 169 seconds) breaches
- Cq=11, T=150: Here, the total delay induced by the attacker ('q*d' = 143 seconds) does not
- Dq=19, T=260: Despite the attacker's increased effort, the total delay ('q*d' = 247 seconds) does
How the community answered
(50 responses)- A70% (35)
- B16% (8)
- C4% (2)
- D10% (5)
Why each option
The scenario where 'q=17' and 'd=13' results in a total delay of 221 seconds, which exceeds the threshold 'T=220', will most likely trigger an alert.
In this scenario, the total delay is calculated as q * d = 17 * 13 = 221 seconds. Since this calculated total delay of 221 seconds is greater than the defined threshold T=220 seconds, an alert would be triggered. This directly matches the condition specified in the problem statement for an alert.
For q=13, T=180, the total delay is 13 * 13 = 169 seconds. This delay (169) does not breach the threshold (180), so an alert would not be triggered.
For q=11, T=150, the total delay is 11 * 13 = 143 seconds. This delay (143) does not breach the threshold (150), so an alert would not be triggered.
For q=19, T=260, the total delay is 19 * 13 = 247 seconds. This delay (247) does not breach the threshold (260), so an alert would not be triggered.
Concept tested: SQL injection time-based detection logic
Topics
Community Discussion
No community discussion yet for this question.