
EC-CouncilCertified Security Specialist
Domain 6Objective 4
Investigating Web Attacks ECSS Practice Questions (Page 6)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
9concepts
Questions 26–30
- 26
Which of the following is a common web attack vector that exploits user-supplied input to execute arbitrary commands on the server?
Select an answer first - 27
A web server was compromised. You have a packet capture that shows an HTTP POST to /upload.php with a multipart form containing a file named 'shell.php'. The server responded with 200 OK. Immediately after, there is an outbound TCP connection from the server to IP 192.0.2.10 on port 4444. Which conclusion is best supported by this network evidence?
Select an answer first - 28
A web application allows users to upload profile pictures. An attacker uploads a file named 'photo.php' that contains PHP code. The server executes the file when accessed. Which web attack vector does this scenario describe?
Select an answer first - 29
A forensic investigator is writing a report on a web attack. The report must be used in court. Which practice is most important for the report to be admissible?
Select an answer first - 30
An analyst is reviewing logs from a web application that was compromised. The access log shows a request to /search?q=<script>alert(1)</script>. The application log shows that the search term was stored in a database. The database log shows the stored term was later retrieved and rendered in a page. Which type of XSS attack is indicated by this evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.