CHFI Final Study Set
Possible Web Application Threats are. (Choose 3)
Application
CrossSite Scripting (XSS)
perform seizure
Buffer Overflow
Integrity
Unvalidated Input
CrossSite Scripting (XSS)
Buffer Overflow
Unvalidated Input
Look for SQL injection assault incidents inside the following locations: (Choose four)
SIEM-brought on signals
System report
Web server log documents
WAF log files
Task log
IDS log files
SIEM-triggered alerts
Web server log files
WAF log documents
IDS log documents
Intrusion Detection Tool: Snort is an open-source community IDS able to acting actual-time
visitors evaluation and packet logging on IP networks.
True
False
True
The default locations of error logs for Apache server errors logs are as follows: (Choose 4)
ebian/Ubuntu Linux: /home windows/log/apache2/error.Log
Debian/Ubuntu Linux: /var/log/apache2/mistakes.Log
FreeBSD: /var/log/httpd-error.Log
, RHEL/Red Hat/CentOS/Fedora Linux:
/log/httpd/error_log
RHEL/Red Hat/CentOS/Fedora Linux: /var/log/httpd/error_log
Debian/Ubuntu Linux: /var/log/apache2/mistakes.Log
FreeBSD: /var/log/httpd-errors.Log
RHEL/Red Hat/CentOS/Fedora Linux: /var/log/httpd/error_log
IDS is a safety software or hardware tool that inspects all inbound and outbound network log for
suspicious styles that may imply a community or system security breach
True
False
False
Investigating Web Attacks on Windows-based totally Servers.
One of the stairs is to find out whether the gadget has failed login attempts or locked-out money
owed.
True
False
True
Web application firewalls (WAFs) are deployed to check out, filter and block the incoming and
outgoing HTTP visitors on internet packages. (Choose 3)
delete
investigate
save
filter out
unblock
block
look at
filter
block
An assault vector is a path or way by using which sufferer can gain get admission to to
computer or community assets on the way to deliver an assault payload or reason a malicious
outcome.
True
False
Possible Web Application Threats are. (Choose 3)
Application
CrossSite Scripting (XSS)
perform seizure
Buffer Overflow
Integrity
Unvalidated Input
CrossSite Scripting (XSS)
Buffer Overflow
Unvalidated Input
Look for SQL injection assault incidents inside the following locations: (Choose four)
SIEM-brought on signals
System report
Web server log documents
WAF log files
Task log
IDS log files
SIEM-triggered alerts
Web server log files
WAF log documents
IDS log documents
Intrusion Detection Tool: Snort is an open-source community IDS able to acting actual-time
visitors evaluation and packet logging on IP networks.
True
False
True
The default locations of error logs for Apache server errors logs are as follows: (Choose 4)
ebian/Ubuntu Linux: /home windows/log/apache2/error.Log
Debian/Ubuntu Linux: /var/log/apache2/mistakes.Log
FreeBSD: /var/log/httpd-error.Log
, RHEL/Red Hat/CentOS/Fedora Linux:
/log/httpd/error_log
RHEL/Red Hat/CentOS/Fedora Linux: /var/log/httpd/error_log
Debian/Ubuntu Linux: /var/log/apache2/mistakes.Log
FreeBSD: /var/log/httpd-errors.Log
RHEL/Red Hat/CentOS/Fedora Linux: /var/log/httpd/error_log
IDS is a safety software or hardware tool that inspects all inbound and outbound network log for
suspicious styles that may imply a community or system security breach
True
False
False
Investigating Web Attacks on Windows-based totally Servers.
One of the stairs is to find out whether the gadget has failed login attempts or locked-out money
owed.
True
False
True
Web application firewalls (WAFs) are deployed to check out, filter and block the incoming and
outgoing HTTP visitors on internet packages. (Choose 3)
delete
investigate
save
filter out
unblock
block
look at
filter
block
An assault vector is a path or way by using which sufferer can gain get admission to to
computer or community assets on the way to deliver an assault payload or reason a malicious
outcome.
True
False