Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 6Objective 4

Investigating Web Attacks ECSS Practice Questions (Page 7)

Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.

53questions here
11free pages
9concepts

Questions 31–35

  1. 31foundation · easy

    What is the primary purpose of obfuscating JavaScript code in web-based malware?

    Select an answer first
  2. 32foundation · easy

    What is the primary impact of a successful cross-site scripting (XSS) attack on a web application?

    Select an answer first
  3. 33foundation · easy

    What is the primary goal of correlating evidence from multiple sources during a web attack investigation?

    Select an answer first
  4. 34application · easy

    You are analyzing Apache access logs and notice a series of requests to /index.php?page=../../../../etc/passwd. What type of attack does this pattern indicate?

    Select an answer first
  5. 35application · medium

    A forensic investigator is reviewing the IIS logs of a compromised web server. The logs show a long series of requests to /product.aspx?id=1, /product.aspx?id=2, and so on, followed by a request to /product.aspx?id=1' AND '1'='1. Later, a request to /admin/upload.aspx with a POST containing a .aspx file appears. Which attack pattern do these logs most clearly indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.