
EC-CouncilDigital Forensics Essentials
Domain 5Objective 4
Web Application Forensics DFE Practice Questions (Page 7)
Part of the Network and Web Attack Forensics domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
10concepts
Questions 31–35
- 31
An analyst is correlating WAF and web server logs after a suspected breach. The WAF log shows a request to /admin.php that was blocked with a 403. The web server log shows the same request with a 200. The timestamps match within one second. What is the most likely explanation?
Select an answer first - 32
Which database log type records the actual SQL statements executed against the database?
Select an answer first - 33
Which component of a web application architecture is typically a separate server that stores structured data and responds to queries from the application server?
Select an answer first - 34
What is the primary purpose of correlating logs from multiple sources (e.g., web server, WAF, database) during a web attack investigation?
Select an answer first - 35
In an HTTP request, which method is used to submit data to the server, typically causing a change in server state?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.