CHFI Application, Email and Cloud Forensics Practice Question
A security analyst reviews Apache access logs and finds the following entry: `192.168.1.10 - - [12/Jul/2024:10:15:30 -0400] "GET /search.php?q=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 5321 "-" "Mozilla/5.0"`. Which attack technique is most likely being attempted?
⚠ Common exam trap
Many exam-takers confuse the `UNION SELECT` SQL syntax with a file inclusion or XSS payload, but the presence of a single quote and SQL keywords specifically indicates SQL injection, not other web attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
The log entry shows a GET request to `/search.php?q=1' UNION SELECT username,password FROM users--`. The single quote (`'`) breaks out of the SQL string context, and the `UNION SELECT` clause attempts to retrieve data from the `users` table. This is a classic SQL injection (SQLi) attack targeting the backend database, as the injected SQL syntax is designed to manipulate the query executed by the application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remote file inclusion
Why it's wrong here
Remote file inclusion (RFI) abuses server-side file inclusion functions, such as PHP's include(), to load and execute a malicious file from an external URL, typically through payloads containing http://, ftp://, or data:// wrappers in request parameters like ?page=. A UNION SELECT statement is SQL syntax that combines database query results; it neither specifies a remote resource nor triggers a file system include operation. The observed log entry therefore indicates an attack against the database layer, not a remote file inclusion attempt.
- ✓
SQL injection
Why this is correct
The presence of UNION SELECT in a query parameter is a classic, definitive indicator of in-band SQL injection. An attacker appends a UNION-based query to the original SQL statement that the application executes against the backend database; if the attacker correctly matches the number and data types of the original query's columns, the database returns the attacker's chosen rows alongside the legitimate results, enabling data exfiltration. This technique operates entirely within the database engine and does not involve remote file loading, client-side script execution, or filesystem path traversal, making the log evidence fully consistent with an automated SQL injection probe.
- ✗
Cross-site scripting (XSS)
Why it's wrong here
Cross-site scripting (XSS) requires the injection of client-side executable content, such as <script> tags, event handlers like onerror=alert(1), or javascript: URIs, that the victim's browser renders and executes after the server reflects or stores the payload. A UNION SELECT statement is pure SQL syntax containing no HTML, JavaScript, or other browser-interpreted content; it is processed server-side by the database and never executed in the client's browser. Therefore, the log entry represents a server-side SQL injection attack, not a client-side XSS payload.
- ✗
Directory traversal
Why it's wrong here
Directory traversal attacks exploit insufficient file path sanitization by using ../ sequences or URL-encoded variants like %2e%2e%2f to navigate outside the web root and read arbitrary files, typically through parameters that specify a file path, template name, or page name. The payload UNION SELECT is not a filesystem path expression and contains no directory traversal characters; it is SQL syntax that the database parser interprets. Because the attack targets SQL query logic rather than file path resolution, the log entry is a clear indicator of SQL injection, not directory traversal.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.