
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 5)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 21–25
- 21
Why is it important to correlate network captures with application logs during a web attack investigation?
Select an answer first - 22
Which of the following is a volatile artifact that should be collected first during a web attack investigation?
Select an answer first - 23
An investigator is examining a web application's source code after a suspected SQL injection attack. Which code pattern would most strongly confirm the vulnerability that was exploited?
Select an answer first - 24
After a web attack, an investigator needs to recover artifacts from a compromised server. Which artifact is most likely to contain the attacker's in-memory exploit code?
Select an answer first - 25
A company has experienced a web attack. The incident response team needs to define the scope and objectives of the forensic investigation. Which statement best defines the primary objective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.