CHFI Application, Email and Cloud Forensics Practice Question
An analyst reviews an Apache access log entry: '192.168.1.10 - - [10/Oct/2023:13:55:36 +0000] "GET /index.php?id=1%27%20OR%20%271%27%3D%271 HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. Which attack does this log entry most likely indicate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection (SQLi) attack
The URL-encoded payload contains SQL injection syntax (%27 is a single quote), attempting to inject an OR condition. This is indicative of a SQL injection attempt.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SQL injection (SQLi) attack
Why this is correct
The log entry contains classic SQL injection signatures: quote characters, SQL logical operators such as OR and AND, and observable query fragments like UNION SELECT. These tokens indicate an attempt to terminate a string literal and append a new SQL predicate to manipulate the database's response. A successful injection of this nature could allow an attacker to bypass authentication, extract data, or modify records, making this the correct classification.
- ✗
Cross-site scripting (XSS) attack
Why it's wrong here
Cross-site scripting attacks are characterized by injected client-side code, typically <script> tags, event handler attributes (onerror, onload), or javascript: URIs, all designed to execute in a victim's browser. The observed payload contains none of these indicators; instead, it uses SQL-specific syntax such as quotes and boolean operators. XSS targets the client-side DOM, whereas the log entry shows an attempt to affect the server-side SQL query parser, so this verdict is incorrect.
- ✗
Path traversal attack
Why it's wrong here
Path traversal attacks rely on directory traversal sequences like ../, ..\, or encoded variants (%2e%2e%2f) to escape the web root and access sensitive files such as /etc/passwd or web.config. The log entry's payload is devoid of these sequential dot-dot-slash patterns and instead presents SQL artifacts like single quotes and OR clauses. Since the request is aimed at query manipulation rather than filesystem navigation, path traversal does not apply here.
- ✗
Remote file inclusion (RFI) attack
Why it's wrong here
Remote file inclusion attacks append external URLs — generally http:// or https:// — often with embedded file names or shell payloads, to dynamic include parameters so the server executes remote code. The logged request carries SQL tokens, not a remote resource locator, and there is no evidence of an external host being referenced. RFI compromises server-side file inclusion mechanisms, whereas this payload is clearly targeting a database's SQL interpreter, making this classification wrong.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.