CEH Web Application and Injection Attacks Practice Question
A security analyst is reviewing a web application log and sees the following request: GET /page?file=../../../etc/passwd HTTP/1.1. Which TWO vulnerabilities are most likely being attempted? (Select two)
⚠ Common exam trap
CEH often tests the overlap between directory traversal and LFI — candidates frequently pick RFI because they see 'file=' and assume remote inclusion, but the payload's local path (`/etc/passwd`) rules RFI out.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Directory traversal
Option A (Directory traversal) is correct because the payload ../../../etc/passwd uses dot-dot-slash sequences to escape the web root and reference files outside the intended directory, which is the classic signature of a path traversal attack. Option D (Local file inclusion) is correct because the same traversal sequence is being passed to the file parameter to make the application include a local server-side file such as /etc/passwd, a hallmark of LFI attempts. Option B (RFI) is not indicated because the value references a local path rather than a remote URL or protocol such as http:// or ftp://. Option C (SQL injection) is not indicated because there are no SQL metacharacters, quotes, or query fragments in the payload. Option E (Command injection) is not indicated because no shell operators or system commands (e.g., ;, |, &&, whoami) appear in the request.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Directory traversal
Why this is correct
Directory traversal, also known as path traversal, is an attack that exploits insufficient security validation or sanitization of user-supplied input to access files and directories stored outside the intended web root directory. The `../` sequence, or its URL-encoded equivalent `%2e%2e%2f`, allows an attacker to navigate up the directory hierarchy. By chaining multiple `../` sequences, an attacker can potentially access sensitive system files like `/etc/passwd` or configuration files, thereby compromising the system's confidentiality.
- ✗
Remote file inclusion (RFI)
Why it's wrong here
Remote File Inclusion (RFI) vulnerabilities occur when a web application incorporates a remote file, specified by a URL, into the server-side script without proper validation. This allows an attacker to execute malicious code hosted on an external server. The provided log entry, however, shows a local path (`../`), not an external URL (e.g., `http://malicious.com/shell.txt`), indicating that the attempt is to access a file on the local system, not to include a remote one.
- ✗
SQL injection
Why it's wrong here
SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution. This typically involves manipulating database queries through input like single quotes, `OR 1=1`, or `UNION SELECT` clauses. The log entry displays a file path (`../`), which bears no resemblance to SQL syntax or common injection patterns, thus ruling out an SQL injection attempt.
- ✓
Local file inclusion (LFI)
Why this is correct
Local File Inclusion (LFI) is a vulnerability that allows an attacker to include a local file on the server through the web application. While the `../` pattern is indicative of directory traversal, LFI specifically refers to the scenario where the application processes and displays or executes the *content* of the specified local file. If the web application attempts to include the file identified by the traversed path, such as `/etc/passwd`, into its output, it constitutes an LFI vulnerability, potentially leading to information disclosure or remote code execution.
- ✗
Command injection
Why it's wrong here
Command injection is an attack in which the goal is to execute arbitrary commands on the host operating system via a vulnerable application. This typically involves injecting shell metacharacters such as `&`, `|`, `||`, `;`, or backticks (`` ` ``) into user-supplied input that is subsequently passed to a system command. The `../` pattern observed in the log is a path manipulation technique, not a command operator, and does not indicate an attempt to execute OS commands.
Go deeper
Related to this question
Learn chapter
System Hacking
Key term
File Inclusion Attacks
File inclusion attacks exploit web application vulnerabilities to load remote or local files, often allowing attackers to execute code, steal data, or compromise a server.
Key term
SQL injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often to read, modify, or destroy data.
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.