
EC-CouncilDigital Forensics Essentials
Domain 5Objective 4
Web Application Forensics DFE Practice Questions (Page 2)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
10concepts
Questions 6–10
- 6
A database log shows a sudden spike in queries from the application user, including `SELECT * FROM users` and `SELECT * FROM orders` in rapid succession, followed by a `DROP TABLE` command. The web server logs show a corresponding spike in requests to a search endpoint. What is the most likely scenario?
Select an answer first - 7
A database log shows a series of SELECT statements that retrieve large amounts of data from a customer table, occurring outside normal business hours. What should an analyst suspect?
Select an answer first - 8
An analyst is reconstructing an attack timeline. The web server log shows a request to `POST /login` at 12:00:00. The WAF log shows the same request was blocked at 12:00:01. The database log shows a failed login attempt at 12:00:02. The analyst also sees a successful login at 12:00:05 from the same IP. What is the most likely sequence of events?
Select an answer first - 9
A WAF log shows a request to /admin.php that was blocked with a 403. The web server log shows no corresponding request. What does this indicate?
Select an answer first - 10
A WAF log entry shows a request that was blocked with a rule ID matching 'SQL injection'. What does this indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.