Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 312-39 Topic 8 Question 85 Discussion

Actual exam question for Eccouncil's 312-39 exam
Question #: 85
Topic #: 8
[All 312-39 Questions]

John, a SOC analyst, while monitoring and analyzing Apache web server logs, identified an event log matching Regex /(\.|(%|%25)2E)(\.|(%|%25)2E)(\/|(%|%25)2F|\\|(%|%25)5C)/i.

What does this event log indicate?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Edward
1 months ago
Definitely going with C on this one. The regex pattern is a dead giveaway for a directory traversal attempt. Better lock down those web server logs, John!
upvoted 0 times
Catina
9 days ago
I agree, C seems like the most likely option. Directory traversal attacks are quite common.
upvoted 0 times
...
...
Dannette
1 months ago
Haha, I bet John was scratching his head trying to figure this one out. Directory traversal attacks can be tricky to spot sometimes.
upvoted 0 times
...
Cristal
1 months ago
I'm not sure, but I think this could also be a parameter tampering attack. The regex pattern seems to be looking for malicious input in the URL parameters.
upvoted 0 times
...
Azalee
2 months ago
This looks like a classic directory traversal attack to me. The regex pattern searches for suspicious directory traversal patterns, so C is the correct answer.
upvoted 0 times
Shawna
27 days ago
Yes, C) Directory Traversal Attack is the correct answer.
upvoted 0 times
...
Georgeanna
1 months ago
I agree, the regex pattern is specifically looking for directory traversal attacks.
upvoted 0 times
...
...
Millie
2 months ago
I believe it could also be a Parameter Tampering Attack, as the Regex pattern seems to indicate manipulation of parameters.
upvoted 0 times
...
Karrie
2 months ago
I agree with Freeman, the Regex pattern matches the Directory Traversal Attack.
upvoted 0 times
...
Freeman
2 months ago
I think the event log indicates a Directory Traversal Attack.
upvoted 0 times
...

Save Cancel