CHFI Application, Email and Cloud Forensics Practice Question
Which TWO of the following are common indicators of a path traversal attack found in web server logs? (Select 2)
⚠ Common exam trap
EC-Council often tests that candidates recognize both raw and URL-encoded forms of path traversal sequences, as many mistakenly think only the raw '../' is an indicator, overlooking the encoded variant '%2e%2e%2f'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requests containing '../' sequences
Option B is correct because '../' is the canonical directory traversal sequence used to climb out of the web root and reference files outside the intended directory, so its appearance in request paths is a classic path traversal indicator. Option D is correct because '%2e%2e%2f' is the URL-encoded form of '../' (where %2e is '.', and %2f is '/'), and attackers frequently encode traversal sequences to bypass naive filters, making it an equally common log indicator. Option A is not a path traversal indicator; multiple or unusual User-Agent strings relate to client identification, bot activity, or user-agent spoofing, not directory traversal. Option C describes '<script>' tags, which indicate cross-site scripting (XSS) attempts rather than path traversal. Option E describes 'OR 1=1', a SQL injection tautology used to bypass authentication or manipulate queries, not a file-path traversal technique.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Requests containing a large number of User-Agent strings
Why it's wrong here
A large volume of User-Agent strings in traffic is a sign of automated scanning, credential stuffing, or botnet activity, but it does not itself exploit file system path handling. Path traversal indicators are tied to the resource path or query string, where traversal payloads like ../ appear. User-Agent anomalies can coexist with such attacks but are not a common or reliable indicator of path traversal.
- ✓
Requests containing '../' sequences
Why this is correct
The literal '../' sequence is the most direct directory traversal pattern, made of two dots and a slash used to move up one directory level in a hierarchical file system. An attacker appends multiple instances (e.g., ../../../../etc/passwd) to escape the web root and read arbitrary files. Its presence in URI path or parameter values is a primary signature for path traversal detection.
- ✗
Requests containing '<script>' tags
Why it's wrong here
'<script>' tags are the hallmark of cross-site scripting (XSS), where untrusted input is rendered as HTML or JavaScript in a victim's browser, not of server-side path manipulation. Path traversal targets file system navigation through inputs such as file names or paths, whereas XSS targets the HTML/script execution context. Thus, observing '<script>' points strongly to XSS probes, not traversal attempts.
- ✓
Requests containing '%2e%2e%2f'
Why this is correct
'%2e%2e%2f' is the URL-encoded representation of '../', since %2e decodes to '.' and %2f decodes to '/'. Attackers use this encoding to bypass input filters that only block literal '..' strings, relying on the server or intermediate component to decode and interpret it. Detection systems must decode URL components before matching traversal signatures, making this encoded variant a critical path traversal indicator.
- ✗
Requests containing 'OR 1=1'
Why it's wrong here
'OR 1=1' is a classic SQL injection sentinel used to alter WHERE clauses and always return true, not a path traversal payload. Path traversal exploits filesystem APIs by manipulating path arguments, whereas SQL injection exploits database query construction via injected SQL syntax. Therefore this pattern points to database injection attempts, not to directory traversal.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.