Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 5

IIS and Apache Web Server Log Analysis DFE Practice Questions (Page 6)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 26–30

  1. 26foundation · easy

    Which log anomaly is most likely to indicate a web application scanning or enumeration attempt?

    Select an answer first
  2. 27foundation · easy

    Which of the following patterns in web server logs is most likely to indicate a brute-force attack?

    Select an answer first
  3. 28application · medium

    You are analyzing an Apache access log and see the following line: `127.0.0.1 - frank [10/Oct/2024:13:55:36 -0700] "GET /index.html HTTP/1.1" 200 2326 "http://www.example.com/start.html" "Mozilla/5.0"` Which log format is this?

    Select an answer first
  4. 29expert · hard

    An analyst is reviewing Apache logs and sees a high number of requests returning a 500 status code for a specific endpoint `/api/query`. The requests come from a single IP and contain SQL keywords in the query string. What is the most likely explanation?

    Select an answer first
  5. 30application · medium

    An IIS log shows a request to /upload.aspx with a POST method, a status of 302, and a subsequent request to /upload.aspx with a GET method and a status of 200. What does this sequence indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.