Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A security analyst is reviewing Apache access logs and finds repeated requests to /index.php?id=1' OR '1'='1. Which type of attack is MOST likely being attempted?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

The pattern 1' OR '1'='1 is a classic SQL injection payload attempting to bypass authentication or extract data. The single quote and OR condition are characteristic of SQLi.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remote file inclusion

    Why it's wrong here

    Remote file inclusion (RFI) is a server-side vulnerability where an application dynamically includes a file from an external URL via functions like include() or require(), typically triggered by parameters such as ?page=http://evil.com/shell.txt. The observed payload — 1' OR '1'='1 — contains no URL, file path, or remote host reference; it is pure SQL tautology syntax. HTTP logs of an RFI attempt would show a fully-qualified domain in the request, not a single-quoted OR expression. Thus this signature does not match RFI.

  • ✗

    Path traversal

    Why it's wrong here

    Path traversal (directory traversal) exploits insufficient sanitization of file paths, using dot-dot-slash sequences like ../../etc/passwd or URL-encoded variants to read arbitrary files outside the web root. The entry 1' OR '1'='1 lacks any ../ tokens, absolute path references, or percent-encoding associated with traversal. Even if the query parameter were URL-encoded, an encoded single quote and OR statement never resolves to a file-system path component. Therefore, the log entry points to a database-level injection attempt rather than a file-read attack.

  • ✓

    SQL injection

    Why this is correct

    This payload is a textbook SQL injection tautology: placing 1' OR '1'='1 inside a WHERE clause, such as WHERE user='admin' AND pass='1' OR '1'='1', makes the entire predicate evaluate to true, allowing authentication bypass or full table extraction. In an Apache access log, the malicious string can appear as part of the request URI or, less commonly, in the request body when access logging includes POST data. The single quote breaks out of the SQL string literal, and the OR condition forces a true result for every row, which is the definitive indicator of SQL injection testing or exploitation. Any defense should focus on parameterized queries, not input filtering alone, because the payload is syntactically valid SQL.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting involves injecting executable scripts into HTML or JavaScript contexts, with payloads such as <script>alert(document.cookie)</script> or <img src=x onerror=alert(1)>, which are interpreted by the victim's browser. The observed string 1' OR '1'='1 contains no angle brackets, no JavaScript event handlers, and no HTML tags, so it cannot execute client-side code. Even in an HTML-encoded environment, this would only remain a literal string or be evaluated as a SQL expression server-side, not as a script. The absence of script syntax makes XSS an incorrect classification for this log entry.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.