Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

During a forensic investigation of a compromised web server, an analyst finds the following entry in the IIS access log: 192.168.1.5, -, 04/May/2024:14:23:11, GET /scripts/..%5c../windows/system32/cmd.exe, 200. What is the probable attack vector?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Path traversal

The log shows a path traversal attempt using URL-encoded backslashes (%5c) to navigate to cmd.exe. The 200 status indicates the request succeeded. This is a classic path traversal attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Brute force attack

    Why it's wrong here

    A brute-force attack requires many repeated authentication attempts (typically thousands) to guess credentials or session tokens. This log entry shows a single GET request containing a carefully crafted encoded traversal sequence, so it exhibits none of the iterative volume or timing pattern of brute force. The payload is aimed at file-system access, not at password or session guessing, making the classification invalid.

  • ✗

    Cross-site scripting

    Why it's wrong here

    Cross-site scripting (XSS) works by injecting executable client-side scripts, such as <script> tags or event handlers, that run in a victim's browser when a page is rendered. The captured request contains no HTML tags, JavaScript, or HTML-escaped equivalents; instead, ..%5c.. is URL-encoded for a backslash and decodes to ..\.., a server-side path traversal attempt. Since the payload never reaches a browser as markup, the XSS classification does not apply.

  • ✓

    Path traversal

    Why this is correct

    The ..%5c.. sequence is URL encoding where %5c represents a backslash, so the payload decodes to ..\.., the classic directory-traversal prefix used to escape the web root. When processed by a vulnerable IIS server, this allowed an attacker to request files like C:\windows\system32\cmd.exe with the unencoded traversal string intact. The request is a single crafted path with encoded separators, which is precisely the signature of a path traversal attack rather than any of the other categories listed.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection hinges on injecting SQL meta-characters (e.g., quotes, semicolons, UNION SELECT) into a query string to alter its logic or merge statements. This request contains no SQL keywords, quotation marks, or a malformed query fragment — the punctuation present is a URL-encoded backslash and a question mark. It is targeting the file system via a path escape, not a database back end, so the SQL injection verdict cannot be correct.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.