Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A forensic analyst is examining a Docker container image for malware. Which TWO techniques can help analyze the image layers?

⚠ Common exam trap

EC-Council often tests the distinction between image-level commands (docker history, docker save) and container-level commands (docker export), trapping candidates who confuse exporting a container's filesystem with extracting image layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use 'docker history' to view the build history of the image

Option A is correct because 'docker history' displays the image's build history, showing each layer's creation command (from the Dockerfile instructions), sizes, and IDs, which lets a forensic analyst trace what was executed or added during the build and spot suspicious layers. Option D is correct because 'docker save' exports the full image (all layers plus metadata) as a tar archive, which can be extracted to inspect each layer's filesystem contents directly, including deleted or hidden files, without running the container. Option B is not suitable because 'docker images' only lists image names, tags, sizes, and IDs on the host; it provides no layer-level detail. Option C is not the best fit because 'docker inspect' returns image metadata (config, environment, entrypoint, layer digests) but not the actual layer contents or build commands needed for deep layer analysis. Option E is incorrect because 'docker export' flattens a running container's filesystem into a single tar, losing the layer history and structure, and it targets containers rather than images.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use 'docker history' to view the build history of the image

    Why this is correct

    The docker history command lists each layer's creation instruction, size and originating command from the image manifest. This reveals suspicious build steps such as downloads or shell commands, satisfying the need to inspect layer provenance without running the container.

  • ✗

    Use 'docker images' to list all images

    Why it's wrong here

    'docker images' only lists locally stored images with tags, sizes and IDs; it exposes no layer contents, so it cannot help analyse layers for malware. It is tempting as the obvious starting command, but it would be correct when inventorying available images before selecting one for deeper examination.

  • ✗

    Use 'docker inspect' to view the image metadata

    Why it's wrong here

    'docker inspect' returns image configuration and metadata such as environment variables and entrypoint, not the contents of individual filesystem layers, so it cannot reveal malware hidden inside them. It is tempting because it is the standard metadata command, but it would be correct when auditing configuration rather than analysing layer contents.

  • ✓

    Use 'docker save' to export the image as a tar file and extract layers

    Why this is correct

    Exporting with 'docker save' writes the image to a tar archive containing each layer as a separate directory, plus manifests and config JSON. This lets the analyst inspect layer contents offline without a running daemon, satisfying the need to examine image layers for hidden malware.

  • ✗

    Use 'docker export' on a running container

    Why it's wrong here

    'docker export' flattens a running container's filesystem into a single tar archive, discarding the layer history and metadata a forensic analyst needs to attribute artefacts to specific layers. It is tempting because it captures filesystem content, but it would be correct when the requirement is a flat snapshot rather than layer-by-layer analysis.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.