
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 10)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 46–48
- 46
During an investigation of a web breach, an analyst has a network packet capture (PCAP) showing outbound HTTPS traffic from the web server to an external IP, and a proxy log showing a POST request to a URL that matches a known command-and-control pattern. However, the web server's access log does not show the corresponding request. What is the most likely reason for this discrepancy, and what should the analyst do next?
Select an answer first - 47
Which element is essential for a forensic report to be considered admissible in court?
Select an answer first - 48
An investigator is correlating a web attack. The web server access log shows a POST to /upload.php from IP 192.0.2.10 at 12:00:00. The network capture shows the same POST, but the packet payload contains a malicious PHP file. The application log shows the file was saved to /var/www/uploads/shell.php. Which additional evidence would best confirm that the attacker executed the uploaded shell?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CHFI
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.