Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A security analyst reviews an Apache access log entry: 192.168.1.5 - - [10/Jan/2024:08:12:35 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 4321 "-" "Mozilla/5.0". What type of attack is MOST likely indicated?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

The log entry shows a UNION SELECT statement appended to the id parameter, which is a classic SQL injection attempt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    The log entry contains SQL UNION syntax, whereas XSS payloads rely on script tags, event handlers like onerror, or javascript: URIs that execute in the victim's browser. XSS attacks target client-side interpretation of dynamic HTML, not the server-side database query. A UNION SELECT clause is a structured query language operation that fuses result sets from the database, which has no effect on raw HTML rendering. Therefore, the observed payload does not match the injection pattern expected for cross-site scripting.

  • ✗

    Path traversal

    Why it's wrong here

    Path traversal typically constructs sequences such as ../../etc/passwd or encoded variants like %2e%2e%2f to escape the webroot and read arbitrary files. The apache log entry cited here does not contain any dot-dot-slash or similar traversal pattern; it contains the SQL keyword UNION SELECT. Path traversal manipulates file path strings used by file system functions, while UNION SELECT manipulates a database query. Hence the attack is not a path traversal.

  • ✗

    Remote file inclusion

    Why it's wrong here

    Remote File Inclusion requires the attacker to supply an external resource URL, e.g., http://evil.com/shell.txt or ftp://attacker/payload, in a parameter that is passed to an include function such as PHP's include() or require(). The log entry shows no URL scheme or external host; the payload is SQL syntax. RFI seeks to execute a remotely hosted script on the web server, whereas UNION SELECT merely extends an SQL result set to extract database content. The absence of any URI-based payload rules out RFI.

  • ✓

    SQL injection

    Why this is correct

    The presence of UNION SELECT in the request parameter is a hallmark of in-band SQL injection. By injecting a quote to close the original SQL string and then using UNION, the attacker can append arbitrary columns to the result set and exfiltrate data from other tables. The server-side SQL query executes the combined statement, and the output is reflected in the HTTP response, allowing non-blind data extraction. This is why the log entry is correctly classified as SQL injection.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.