
EC-CouncilCertified Security Specialist
Domain 6Objective 4
Investigating Web Attacks ECSS Practice Questions (Page 2)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
9concepts
Questions 6–10
- 6
A network capture from a web server shows a series of HTTP requests with varying 'Host' headers, each requesting the same URL. The responses vary in content. Which attack is most likely being performed?
Select an answer first - 7
A forensic investigator is examining a pcap file from a web server that was defaced. The capture shows an HTTP request with a GET /admin?debug=true&cmd=whoami request followed by a response containing the output of the 'whoami' command. Which finding best characterizes the attack based on this network traffic?
Select an answer first - 8
A web application allows users to upload profile pictures. An attacker uploads a file named 'photo.php' disguised as a JPEG. When the file is accessed, it executes PHP code. Which web attack vector is being exploited?
Select an answer first - 9
During an investigation, an analyst notices that an attacker first performed a port scan, then exploited a known vulnerability in the web server, and finally installed a backdoor. Which phase of the attack methodology does the backdoor installation represent?
Select an answer first - 10
You are reconstructing a web attack timeline. Evidence sources include: (1) web server logs showing a successful login from a new IP at 10:00; (2) a memory dump showing a process injected with a reverse shell at 10:05; (3) network captures showing outbound traffic to a known C2 server at 10:10; (4) database logs showing a large data export at 10:15. Which timeline is most consistent with this evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.