
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 2)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 6–10
- 6
Which data source would provide the most complete view of a web attack that involved multiple requests from different IP addresses?
Select an answer first - 7
During a web attack investigation, the investigator must preserve evidence but the server is a critical production system that cannot be taken offline. Which approach best balances forensic soundness with operational continuity?
Select an answer first - 8
A web server's access log shows a series of requests to /product.php?id=1, /product.php?id=2, and so on, up to /product.php?id=1000, all from the same IP within 30 seconds. The site's product IDs are UUIDs. Which log analysis step would most directly confirm whether this is an automated enumeration attempt?
Select an answer first - 9
A forensic investigator is tracing a web attack. The web server access log shows a POST to /login.php from IP 203.0.113.5 at 10:00:00. The application log shows a successful login for user 'admin' at 10:00:01. The network capture shows a TCP handshake from 203.0.113.5 to the server at 09:59:59. Which conclusion is best supported by correlating these data sources?
Select an answer first - 10
When examining web application source code for forensic purposes, what is the investigator primarily looking for?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.