
EC-CouncilCertified Security Specialist
Domain 6Objective 4
Investigating Web Attacks ECSS Practice Questions (Page 1)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
9concepts
Questions 1–5
- 1
When analyzing web server logs, which log entry pattern is most indicative of a SQL injection attempt?
Select an answer first - 2
An attacker is targeting a web application. The network captures show the following sequence: (1) a GET request to /robots.txt; (2) a GET request to /admin/login.php; (3) a POST to /admin/login.php with a username and password; (4) a GET to /admin/dashboard.php with a session cookie. Which attack methodology is most clearly demonstrated?
Select an answer first - 3
Which step in the web attack methodology involves gathering information about the target without directly interacting with the target systems?
Select an answer first - 4
A web application firewall (WAF) blocked a series of requests to a customer portal. The WAF log shows repeated POST requests to /login with increasingly long 'username' parameters, some exceeding 1,000 characters. The application team reports no successful logins during that window. Which log-analysis step would best confirm whether the requests were a SQL injection attempt rather than a brute-force attack?
Select an answer first - 5
During a web attack investigation, you need to determine if the attacker accessed sensitive data from the database. Which evidence source would be most direct for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.