Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 5Objective 5

IIS and Apache Web Server Log Analysis DFE Practice Questions (Page 8)

Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.

42questions here
9free pages
8concepts

Questions 36–40

  1. 36foundation · easy

    Which command would you use to extract the second field from each line of a log file, where fields are separated by spaces?

    Select an answer first
  2. 37application · medium

    An IIS log entry shows: 2023-10-05 09:30:15 192.168.1.20 GET /index.php?id=1 UNION SELECT username,password FROM users - 200 0 0 2345 6789. Which attack is indicated, and which field contains the malicious payload?

    Select an answer first
  3. 38application · medium

    You are comparing Apache common and combined log formats. Which field is present in the combined format but NOT in the common format?

    Select an answer first
  4. 39expert · hard

    An analyst is comparing IIS and Apache logs for the same web application. The IIS log shows a request to /index.php?id=1 UNION SELECT password FROM users with a 200 status. The Apache log shows the same request with a 200 status. Which conclusion is most accurate?

    Select an answer first
  5. 40application · medium

    While analyzing Apache logs, you find the following request: `GET /cgi-bin/../../../../etc/passwd HTTP/1.1` with a 200 status code. Which attack is indicated?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.