QuestionQ433
Logs and Network ForensicsDuring a late-night incident at an e-commerce site in Houston, Texas, analysts observe bursts of database errors and high time-taken values in IIS logs that align with requests in which attackers reportedly appended encoded input to the URL. To isolate and compare the exact payload strings against these spikes, which IIS W3C field should investigators parse?
- A cs-uri-query
- B cs-uri-stem
- C sc-status
- D cs-method
Community Discussion