CHFI Application, Email and Cloud Forensics Practice Question
A security analyst reviews an Apache access log and finds the entry: '192.168.1.10 - - [10/Mar/2025:08:12:34 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 2345 "-" "Mozilla/5.0"'. Which attack is indicated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
The UNION SELECT statement in the URI indicates a SQL injection attack. The attacker is trying to extract data from the database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
Cross-site scripting (XSS) attempts exploit the trust a user has for a website by injecting malicious JavaScript or HTML into application output. In access logs, these attempts typically appear as encoded script tags or event handler attributes in parameters, not as SQL keywords. A request containing 'UNION SELECT' reflects attacker manipulation of a database query, which is outside the client-side context XSS operates in. Therefore, the observed log signature does not match XSS.
- ✓
SQL injection
Why this is correct
The UNION SELECT clause visible in the access log is a classic signature of UNION-based SQL injection. An attacker injects this clause to merge a legitimate query with an arbitrary SELECT statement, allowing retrieval of data from unrelated tables, such as user credentials or payment records. This technique is specifically designed to manipulate the database query structure rather than client-side content, file paths, or upload endpoints, making it the only answer that matches the observed log evidence.
- ✗
Path traversal
Why it's wrong here
Path traversal, also known as directory traversal, leverages '../' or its encoded variants to escape the web root and access sensitive local files, such as /etc/passwd or application configuration files. The request line in the log demonstrates SQL injection keywords, which have no relationship to filesystem path manipulation. Furthermore, path traversal attacks target the server's file system, not the back-end database, so the presence of 'UNION SELECT' clearly excludes this classification.
- ✗
Webshell upload
Why it's wrong here
A webshell upload involves sending a malicious file, typically via HTTP POST to an upload handler, with a filename extension like .php or .jsp and embedded server-side code. The described Apache log entry centers on a GET request with SQL keywords, which is completely different from a file-upload transaction. Additionally, webshell attacks usually require a second request to execute the uploaded file, and would not produce a 'UNION SELECT' clause in the initial request string, so this option is incompatible.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on CHFI
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An analyst examines the following Apache access log entry: 192.168.1.10 - - [10/Jan/2023:13:45:22 +0000] "GET /search.php?q=1%27%20UNION%20SELECT%201,2,3-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0". Which attack is MOST likely indicated?
easy- A.Path Traversal
- ✓ B.SQL Injection
- C.Cross-Site Scripting (XSS)
- D.Remote File Inclusion
Why B: The log shows a UNION SELECT statement in the query parameter, indicating a SQL injection attempt. The URL-encoded single quote (') and comment (--) are classic SQLi payloads.
Variation 2. An analyst reviews an Apache access log entry: '192.168.1.10 - - [10/Oct/2023:13:55:36 +0000] "GET /index.php?id=1%27%20OR%20%271%27%3D%271 HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. Which attack does this log entry most likely indicate?
medium- ✓ A.SQL injection (SQLi) attack
- B.Cross-site scripting (XSS) attack
- C.Path traversal attack
- D.Remote file inclusion (RFI) attack
Why A: The URL-encoded payload contains SQL injection syntax (%27 is a single quote), attempting to inject an OR condition. This is indicative of a SQL injection attempt.
Variation 3. A security analyst reviews an Apache access log entry: 192.168.1.5 - - [10/Jan/2024:08:12:35 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 4321 "-" "Mozilla/5.0". What type of attack is MOST likely indicated?
easy- A.Cross-site scripting (XSS)
- B.Path traversal
- C.Remote file inclusion
- ✓ D.SQL injection
Why D: The log entry shows a UNION SELECT statement appended to the id parameter, which is a classic SQL injection attempt.
Variation 4. A security analyst reviews the following Apache access log entry: 192.168.1.10 - - [15/May/2025:10:15:23 +0000] "GET /search.php?q=1'%20OR%20'1'='1 HTTP/1.1" 200 5321 "-" "Mozilla/5.0". Which type of attack is most likely indicated?
medium- A.Cross-site scripting (XSS)
- B.Path traversal
- C.Remote file inclusion
- ✓ D.SQL injection (SQLi)
Why D: The log entry shows a GET request to /search.php with the parameter q containing the payload 1' OR '1'='1. This is a classic SQL injection (SQLi) attempt, where the attacker injects a tautology (OR '1'='1') to manipulate the SQL query's WHERE clause, potentially bypassing authentication or extracting data. The URL-encoded single quote (%27) and the OR condition are definitive indicators of SQLi.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.