
EC-CouncilDigital Forensics Essentials
Domain 5Objective 5
IIS and Apache Web Server Log Analysis DFE Practice Questions (Page 5)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
42questions here
9free pages
8concepts
Questions 21–25
- 21
What is the primary difference between the Apache Common Log Format (CLF) and the Combined Log Format?
Select an answer first - 22
An administrator notices a sudden spike in 404 errors in the Apache access log, all from the same IP, with a user agent of 'Mozilla/5.0 (compatible; Nmap Scripting Engine)'. The requests target paths like /admin, /backup, and /config. Which command would best summarize the attack pattern for a report?
Select an answer first - 23
In web server logs, what does HTTP status code 404 indicate?
Select an answer first - 24
An analyst is reviewing Apache logs and finds the following request: `GET /product.php?id=1%20AND%201=1` with a 200 status code. Which attack is most likely being attempted?
Select an answer first - 25
You are parsing an IIS log entry and need to extract the client IP address. The entry is: `2024-08-01 08:30:00 198.51.100.7 POST /submit.aspx 200 Mozilla/5.0` Which field is the client IP?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.