CHFI Application, Email and Cloud Forensics Practice Question
A security analyst reviewing Apache access logs finds entries like: 192.168.1.10 - - [12/Jan/2023:15:23:11 +0000] "GET /search?q=1' OR '1'='1 HTTP/1.1" 200 5324. What attack is indicated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
The log entry shows a SQL injection attempt via the 'q' parameter with a tautology. The 200 response indicates the request was processed, suggesting possible success.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
Cross-site scripting (XSS) is a client-side vulnerability that occurs when an application reflects unsanitized user input into a web page, allowing an attacker to inject executable JavaScript (typically via <script> tags or event handlers) that runs in a victim's browser. The observed payload '1' OR '1'='1' contains no HTML, JavaScript, or event-handler syntax, and it is submitted as a parameter value to a server-side process rather than being stored or reflected as page content. Because the injection target is the backend database query instead of the browser DOM, this entry cannot be classified as XSS, even though both stem from inadequate input validation.
- ✓
SQL injection
Why this is correct
SQL injection occurs when attacker-controlled input is concatenated directly into a SQL statement without parameterization, changing the query's logic. The literal payload '1' OR '1'='1' is a textbook tautology: if placed in a WHERE clause (e.g., WHERE user='admin' AND password='1' OR '1'='1'), it evaluates TRUE for every row, allowing authentication bypass or data exfiltration. Web application firewalls often flag this exact pattern, and the correct remediation is prepared statements/parameterized queries, strict input validation, and least-privilege database accounts.
- ✗
Path traversal
Why it's wrong here
Path traversal (directory traversal) abuses insufficiently sanitized file-path inputs by injecting sequences like ../ or absolute paths to read files outside the web root, such as /etc/passwd on Linux or ..\..\windows\win.ini on Windows. The Apache log entry instead contains an SQL tautology in a parameter that is likely bound to a database query, not a filename or filesystem path. No dot-dot-slash sequences or file system constructs appear, so the attack is targeting the SQL layer, not the file retrieval mechanism.
- ✗
Command injection
Why it's wrong here
Command injection exploits improper sanitization of input that is passed to an operating system shell, allowing an attacker to append commands using delimiters like ;, &&, |, or backticks, such as 'id; ls -la' in a vulnerable CGI script. The payload '1' OR '1'='1' uses SQL operators and numeric literals rather than shell metacharacters or OS command names, and it would not be interpreted as a command by a shell. Even if the input reaches a database, database engines do not execute OS commands through SQL expressions unless deliberately invoked via features like xp_cmdshell—which is not triggered by this tautology.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.