CHFI Application, Email and Cloud Forensics • Set 4
CHFI Application, Email and Cloud Forensics Practice Test 4 — 15 questions with explanations. Free, no signup.
A forensic investigator is analyzing a Linux web server that was compromised through a PHP vulnerability. The attacker uploaded a web shell and executed commands. The investigator needs to determine which command was executed FIRST after the initial compromise. The server uses standard Apache logging with mod_log_config and PHP error logging enabled. Which log source should the investigator examine to find the exact sequence of commands executed by the attacker through the web shell?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.