Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 4

Investigating Web Attacks ECSS Practice Questions (Page 5)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
9concepts

Questions 21–25

  1. 21expert · hard

    A web server was compromised via a drive-by download. You have a memory dump from the server. Which memory artifact would be most indicative of a drive-by download attack?

    Select an answer first
  2. 22foundation · easy

    Which piece of information is most useful for correlating a web server log entry with a network packet capture?

    Select an answer first
  3. 23application · medium

    You are writing a forensic report for a web attack that involved SQL injection and data exfiltration. The report will be reviewed by both legal counsel and IT management. Which section should include the raw SQL injection payloads?

    Select an answer first
  4. 24foundation · easy

    In a systematic web attack methodology, which phase typically follows reconnaissance and involves actively probing the target for vulnerabilities?

    Select an answer first
  5. 25expert · hard

    You are investigating a web attack where the attacker used a previously unknown exploit to gain code execution on the web server. You have a memory dump taken after the attack. Which memory forensics technique would be most effective in identifying the exploit code?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.