Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 4

Investigating Web Attacks ECSS Practice Questions (Page 3)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
9concepts

Questions 11–15

  1. 11application · medium

    After completing a web attack investigation, a forensic analyst must present findings to a non-technical executive board. Which reporting approach is most appropriate for this audience?

    Select an answer first
  2. 12foundation · easy

    What is the primary purpose of the executive summary in a forensic report on a web attack investigation?

    Select an answer first
  3. 13foundation · easy

    Which network traffic characteristic is commonly used to identify a distributed denial-of-service (DDoS) attack in a packet capture?

    Select an answer first
  4. 14expert · hard

    A web application was defaced. You have the following evidence: (1) web server access logs show a successful POST to /upload.php from IP 203.0.113.5 at 02:15 UTC; (2) the uploaded file is a PHP script that creates a backdoor; (3) network captures show an outbound connection from the web server to 198.51.100.7:4444 at 02:20 UTC; (4) the defacement page was first seen at 02:25 UTC. Which conclusion is best supported by correlating these evidence sources?

    Select an answer first
  5. 15application · medium

    An attacker successfully exploited a web application. The web server logs show the following sequence: (1) a GET request to /search.php?q=<script>alert('x')</script>; (2) a POST to /login.php with a username containing SQL syntax; (3) a GET to /admin/users.php with a session cookie. Which attack methodology does this sequence best illustrate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.