Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A security analyst reviews Apache access logs and finds the following entry: `192.168.1.10 - - [12/Jul/2024:10:15:30 -0400] "GET /search.php?q=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 5321 "-" "Mozilla/5.0"`. Which attack technique is most likely being attempted?

⚠ Common exam trap

Many exam-takers confuse the `UNION SELECT` SQL syntax with a file inclusion or XSS payload, but the presence of a single quote and SQL keywords specifically indicates SQL injection, not other web attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL injection

The log entry shows a GET request to `/search.php?q=1' UNION SELECT username,password FROM users--`. The single quote (`'`) breaks out of the SQL string context, and the `UNION SELECT` clause attempts to retrieve data from the `users` table. This is a classic SQL injection (SQLi) attack targeting the backend database, as the injected SQL syntax is designed to manipulate the query executed by the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remote file inclusion

    Why it's wrong here

    Remote file inclusion (RFI) abuses server-side file inclusion functions, such as PHP's include(), to load and execute a malicious file from an external URL, typically through payloads containing http://, ftp://, or data:// wrappers in request parameters like ?page=. A UNION SELECT statement is SQL syntax that combines database query results; it neither specifies a remote resource nor triggers a file system include operation. The observed log entry therefore indicates an attack against the database layer, not a remote file inclusion attempt.

  • ✓

    SQL injection

    Why this is correct

    The presence of UNION SELECT in a query parameter is a classic, definitive indicator of in-band SQL injection. An attacker appends a UNION-based query to the original SQL statement that the application executes against the backend database; if the attacker correctly matches the number and data types of the original query's columns, the database returns the attacker's chosen rows alongside the legitimate results, enabling data exfiltration. This technique operates entirely within the database engine and does not involve remote file loading, client-side script execution, or filesystem path traversal, making the log evidence fully consistent with an automated SQL injection probe.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting (XSS) requires the injection of client-side executable content, such as <script> tags, event handlers like onerror=alert(1), or javascript: URIs, that the victim's browser renders and executes after the server reflects or stores the payload. A UNION SELECT statement is pure SQL syntax containing no HTML, JavaScript, or other browser-interpreted content; it is processed server-side by the database and never executed in the client's browser. Therefore, the log entry represents a server-side SQL injection attack, not a client-side XSS payload.

  • ✗

    Directory traversal

    Why it's wrong here

    Directory traversal attacks exploit insufficient file path sanitization by using ../ sequences or URL-encoded variants like %2e%2e%2f to navigate outside the web root and read arbitrary files, typically through parameters that specify a file path, template name, or page name. The payload UNION SELECT is not a filesystem path expression and contains no directory traversal characters; it is SQL syntax that the database parser interprets. Because the attack targets SQL query logic rather than file path resolution, the log entry is a clear indicator of SQL injection, not directory traversal.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.