
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 6)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 26–30
- 26
Which field in a standard web server access log is most useful for correlating requests from the same source?
Select an answer first - 27
A forensic investigator is analyzing an IIS web server's logs after a suspected SQL injection attack. The investigator notices many HTTP 500 errors in the error log, but the access log shows only a few requests to the vulnerable page. Which log-analysis step would most directly help confirm the attack and identify the injected payload?
Select an answer first - 28
What is the primary purpose of a forensic report in a web attack investigation?
Select an answer first - 29
A company's web application was compromised. The investigation reveals that the attacker used a SQL injection vulnerability to extract data. The web server logs show the attack originated from a single IP address, but the company's firewall logs show the same IP address was used for a brief period. The company's legal team wants to know if the attacker can be identified. Which factor is most critical in determining the likelihood of identifying the attacker?
Select an answer first - 30
An investigator is preparing a forensic report for a web attack. The report must be admissible in court. Which practice is most important to ensure the report's admissibility?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.