
EC-CouncilCertified Security Specialist
Domain 6Objective 4
Investigating Web Attacks ECSS Practice Questions (Page 7)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
53questions here
11free pages
9concepts
Questions 31–35
- 31
What is the primary purpose of obfuscating JavaScript code in web-based malware?
Select an answer first - 32
What is the primary impact of a successful cross-site scripting (XSS) attack on a web application?
Select an answer first - 33
What is the primary goal of correlating evidence from multiple sources during a web attack investigation?
Select an answer first - 34
You are analyzing Apache access logs and notice a series of requests to /index.php?page=../../../../etc/passwd. What type of attack does this pattern indicate?
Select an answer first - 35
A forensic investigator is reviewing the IIS logs of a compromised web server. The logs show a long series of requests to /product.aspx?id=1, /product.aspx?id=2, and so on, followed by a request to /product.aspx?id=1' AND '1'='1. Later, a request to /admin/upload.aspx with a POST containing a .aspx file appears. Which attack pattern do these logs most clearly indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.