
EC-CouncilDigital Forensics Essentials
Domain 5Objective 5
IIS and Apache Web Server Log Analysis DFE Practice Questions (Page 3)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 11–15
- 11
An IIS log entry shows: 2023-10-05 14:22:10 10.0.0.5 GET /search.aspx?q=<script>alert(1)</script> - 200 0 0 1234 5678. Which fields confirm a cross-site scripting attempt, and what does the 200 status indicate?
Select an answer first - 12
In the Apache log entry: '192.168.1.10 - - [15/Mar/2024:10:22:33 +0000] "GET /index.html HTTP/1.1" 200 1024', what does '1024' represent?
Select an answer first - 13
An analyst is investigating a potential web attack. The Apache logs show a series of requests from the same IP to `/search.php?q=<script>alert(1)</script>` with a 200 status code. Which attack is indicated?
Select an answer first - 14
An analyst is reviewing IIS logs and sees a high number of requests returning a 403 status code for a specific directory. What does this pattern most likely indicate?
Select an answer first - 15
An analyst is reconstructing an attack timeline from Apache logs. The logs show: a 404 for /admin, then a 200 for /admin/login.php, then a 302 for /admin/index.php, then a 200 for /admin/users.php?delete=1. What is the most likely sequence of events?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.