
EC-CouncilDigital Forensics Essentials
Domain 5Objective 4
Web Application Forensics DFE Practice Questions (Page 1)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
10concepts
Questions 1–5
- 1
A web server log shows a request: `GET /download.php?file=../../../../etc/passwd HTTP/1.1` with a response of HTTP 200 and the content of `/etc/passwd` in the body. What does this indicate?
Select an answer first - 2
In a typical three-tier web application architecture, which component is responsible for executing business logic and coordinating data access?
Select an answer first - 3
What is the primary purpose of a Web Application Firewall (WAF) log?
Select an answer first - 4
An analyst is reviewing HTTP traffic and sees the following request: `POST /search HTTP/1.1` `Host: example.com` `Content-Type: application/x-www-form-urlencoded` `Cookie: sessionid=abc123` `q=product%22%3E%3Cscript%3Ealert(1)%3C/script%3E` The response is HTTP 200 and contains the input reflected in the page. The WAF log shows no block for this request. What is the most likely vulnerability?
Select an answer first - 5
A forensic analyst notices many requests to '/admin/login.php' from different IP addresses in a short time. Which pattern does this likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.