
EC-CouncilDigital Forensics Essentials
Domain 5Objective 5
IIS and Apache Web Server Log Analysis DFE Practice Questions (Page 2)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 6–10
- 6
Which of the following is a typical field found in an IIS log entry that records the HTTP method used in the request?
Select an answer first - 7
An analyst is reviewing Apache logs and notices a high number of requests with a 404 status, all from the same IP, with a user agent of 'python-requests/2.31'. The requests target random paths with names like /wp-login.php, /admin, and /test. What is the most likely explanation, and which command would confirm the pattern?
Select an answer first - 8
In an IIS log file using the W3C Extended Log Format, which field is used to record the IP address of the client that made the request?
Select an answer first - 9
In an Apache Common Log Format (CLF) entry, which of the following fields is NOT present?
Select an answer first - 10
When reconstructing the timeline of an attack from web server logs, what is the first step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.