Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 4

Investigating Web Attacks ECSS Practice Questions (Page 10)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
9concepts

Questions 46–50

  1. 46foundation · easy

    Which type of digital evidence can capture the exact network packets exchanged during a web attack?

    Select an answer first
  2. 47application · medium

    During a web attack investigation, you found a suspicious JavaScript file that was served to users. You need to determine if it is malicious and what it does. Which approach would be most effective?

    Select an answer first
  3. 48application · medium

    An analyst is reviewing the IIS logs of a web server and finds the following entry: 'GET /products.aspx?id=1;DROP TABLE Products--'. Which attack is indicated by this log entry?

    Select an answer first
  4. 49foundation · easy

    Which of the following is a common technique used to analyze a suspicious JavaScript file without executing it?

    Select an answer first
  5. 50expert · hard

    During a web attack investigation, a memory dump from a compromised web server is available. The investigator finds an encoded PowerShell command in the memory of the w3wp.exe process. The command decodes to a script that downloads a second-stage payload from a remote server. Which additional memory artifact would most directly help identify the malware's persistence mechanism?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.