
EC-CouncilCertified Security Specialist
Domain 6Objective 4
Investigating Web Attacks ECSS Practice Questions (Page 3)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
9concepts
Questions 11–15
- 11
After completing a web attack investigation, a forensic analyst must present findings to a non-technical executive board. Which reporting approach is most appropriate for this audience?
Select an answer first - 12
What is the primary purpose of the executive summary in a forensic report on a web attack investigation?
Select an answer first - 13
Which network traffic characteristic is commonly used to identify a distributed denial-of-service (DDoS) attack in a packet capture?
Select an answer first - 14
A web application was defaced. You have the following evidence: (1) web server access logs show a successful POST to /upload.php from IP 203.0.113.5 at 02:15 UTC; (2) the uploaded file is a PHP script that creates a backdoor; (3) network captures show an outbound connection from the web server to 198.51.100.7:4444 at 02:20 UTC; (4) the defacement page was first seen at 02:25 UTC. Which conclusion is best supported by correlating these evidence sources?
Select an answer first - 15
An attacker successfully exploited a web application. The web server logs show the following sequence: (1) a GET request to /search.php?q=<script>alert('x')</script>; (2) a POST to /login.php with a username containing SQL syntax; (3) a GET to /admin/users.php with a session cookie. Which attack methodology does this sequence best illustrate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.