Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 5

IIS and Apache Web Server Log Analysis DFE Practice Questions (Page 5)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 21–25

  1. 21foundation · easy

    What is the primary difference between the Apache Common Log Format (CLF) and the Combined Log Format?

    Select an answer first
  2. 22application · medium

    An administrator notices a sudden spike in 404 errors in the Apache access log, all from the same IP, with a user agent of 'Mozilla/5.0 (compatible; Nmap Scripting Engine)'. The requests target paths like /admin, /backup, and /config. Which command would best summarize the attack pattern for a report?

    Select an answer first
  3. 23foundation · easy

    In web server logs, what does HTTP status code 404 indicate?

    Select an answer first
  4. 24expert · hard

    An analyst is reviewing Apache logs and finds the following request: `GET /product.php?id=1%20AND%201=1` with a 200 status code. Which attack is most likely being attempted?

    Select an answer first
  5. 25application · medium

    You are parsing an IIS log entry and need to extract the client IP address. The entry is: `2024-08-01 08:30:00 198.51.100.7 POST /submit.aspx 200 Mozilla/5.0` Which field is the client IP?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.