
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 8)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 36–40
- 36
A web server's access log shows a series of requests that appear to be a SQL injection attack, but the web application uses parameterized queries. The network capture shows the same requests, but the application log shows no errors or unusual behavior. Which conclusion is best supported?
Select an answer first - 37
A forensic team is investigating a web attack that involved a drive-by download. The compromised user's machine has been powered off, and the investigator needs to recover evidence of the malicious script execution. Which of the following artifacts would be most valuable to recover from the machine's disk?
Select an answer first - 38
An investigator is correlating network captures with web server logs to trace a web attack. Which finding would best confirm that a request seen in the network capture actually reached the web application?
Select an answer first - 39
An investigator is writing a forensic report for a web attack. The report includes a timeline of events, but the investigator is unsure whether to include the raw log excerpts. What is the best practice?
Select an answer first - 40
An investigator is reviewing web application source code after a file upload attack. Which code pattern is most likely the vulnerability that allowed the attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.