Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 5Objective 1

Investigating Web Attacks CHFI Practice Questions (Page 10)

Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
8concepts

Questions 46–48

  1. 46application · medium

    During an investigation of a web breach, an analyst has a network packet capture (PCAP) showing outbound HTTPS traffic from the web server to an external IP, and a proxy log showing a POST request to a URL that matches a known command-and-control pattern. However, the web server's access log does not show the corresponding request. What is the most likely reason for this discrepancy, and what should the analyst do next?

    Select an answer first
  2. 47foundation · easy

    Which element is essential for a forensic report to be considered admissible in court?

    Select an answer first
  3. 48expert · hard

    An investigator is correlating a web attack. The web server access log shows a POST to /upload.php from IP 192.0.2.10 at 12:00:00. The network capture shows the same POST, but the packet payload contains a malicious PHP file. The application log shows the file was saved to /var/www/uploads/shell.php. Which additional evidence would best confirm that the attacker executed the uploaded shell?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CHFI

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.