exam questions

Exam 312-39 All Questions

View all questions & answers for the 312-39 exam

Exam 312-39 topic 1 question 47 discussion

Actual exam question from ECCouncil's 312-39
Question #: 47
Topic #: 1
[All 312-39 Questions]

John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i.
What does this event log indicate?

  • A. XSS Attack
  • B. SQL injection Attack
  • C. Directory Traversal Attack
  • D. Parameter Tampering Attack
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Berro_b
1 week, 2 days ago
Selected Answer: C
p.448 To perform this type of attack, absolute or relative path traversal characters like /,.../, or its encoded versions %2f, %2e%2e%2f, or %2e%2e/ are used to compromise the path. To detect such type of vulnerabilities, set an alert on pattern matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i
upvoted 1 times
...
ayisuska
10 months, 2 weeks ago
Selected Answer: C
Modul 04 page 448 Answer is C. Directory Traversal Attack
upvoted 2 times
...
Man_San
1 year ago
Selected Answer: C
The answer is C Directory Traversal Attack XSS occurs on dynamically generated web pages. Thus, it cannot be the answer here.
upvoted 1 times
...
vjvirus
1 year, 3 months ago
Directory Traversal Attack
upvoted 1 times
...
Bocktw
1 year, 4 months ago
Selected Answer: C
Answer is C.
upvoted 1 times
...
Thiha
1 year, 4 months ago
Answer is C.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago