
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 3)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 11–15
- 11
An investigator is tracing a web attack. The access log shows the attack came from IP 203.0.113.5, but the network capture shows that IP 203.0.113.5 is a known Tor exit node. The attacker also used a spoofed X-Forwarded-For header showing 198.51.100.2. Which conclusion is best supported?
Select an answer first - 12
A forensic team is investigating a web attack that involved a drive-by download. The team has a memory dump from the compromised machine and a network capture. The memory dump shows a suspicious process that made an outbound connection, and the network capture shows the corresponding traffic. However, the team cannot determine what the process did. Which additional artifact would be most useful to understand the process's behavior?
Select an answer first - 13
An investigator is tracing the origin of a web attack. The attacker used a VPN service, and the web server logs show the VPN's exit IP address. Which additional data source would be most useful to potentially identify the attacker's true IP address?
Select an answer first - 14
An investigator is analyzing web server logs after a successful SQL injection attack. The logs show that the attack came from an IP address that is now part of a VPN service's address pool. The investigator has obtained a court order for the VPN provider's logs, but the provider states that they do not keep logs. Which alternative approach is most likely to help identify the attacker?
Select an answer first - 15
In network traffic, which pattern is a signature of a SQL injection attempt?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.