
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 1)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 1–5
- 1
Which of the following is an indicator of compromise (IoC) that might appear in a web server access log?
Select an answer first - 2
What is the primary objective of a web attack investigation?
Select an answer first - 3
A web server log contains the following entry: GET /search.php?q=<script>alert('XSS')</script> HTTP/1.1. Which attack signature does this entry most clearly indicate?
Select an answer first - 4
Which configuration file is commonly examined to identify how a web application handles user input?
Select an answer first - 5
An investigator is tracing the origin of a web attack and has identified the attacker's IP address from the logs. However, the IP address belongs to a cloud provider. What is the most important next step to determine the actual attacker?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.