
EC-CouncilComputer Hacking Forensic Investigator
Domain 5Objective 1
Investigating Web Attacks CHFI Practice Questions (Page 9)
Part of the Web and Dark Web Forensics domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
8concepts
Questions 41–45
- 41
During a web attack investigation, an investigator needs to preserve potential evidence from a compromised web server. Which action best preserves volatile and non-volatile artifacts in a forensically sound manner?
Select an answer first - 42
An investigator has completed the analysis of a web attack and must write the forensic report. Which element is most important for the report to be admissible in court?
Select an answer first - 43
During a web attack investigation, an analyst finds a suspicious outbound connection from the web server to an IP address that is not in the server's allowed list. The connection occurred at 2:00 AM. The web server's access log shows no corresponding inbound request. Which additional data source would be most useful to determine if the outbound connection was initiated by a compromised process?
Select an answer first - 44
An investigator is analyzing a web server's access log to reconstruct an attack. Which log entry pattern is most indicative of a directory traversal attempt?
Select an answer first - 45
An investigator is examining web application code after a data breach. The application uses an ORM (Object-Relational Mapping) framework. The access log shows SQL injection-like patterns, but the ORM is supposed to prevent SQL injection. Which code pattern would explain the apparent SQL injection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.