Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A forensic analyst is examining a Docker container that was used to launch a DDoS attack. Which layer of a Docker image is most likely to contain the attacker's malicious scripts?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The topmost writable container layer

Docker images consist of read-only layers. The topmost writable layer (container layer) holds changes made at runtime, such as installing tools or scripts. The attack scripts would be in this layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The overlay filesystem layer

    Why it's wrong here

    The overlay filesystem is not a discrete layer; it is the union-mount mechanism (e.g., overlay2) that merges multiple lower image layers and the container's upper writable layer into a single unified view. During forensic analysis, you cannot extract artifacts from a layer literally named 'overlay'—instead, you must look at the underlying individual layers or the container's own upper directory. Thus, choosing this option misidentifies the storage driver's glue as a separate layer.

  • ✓

    The topmost writable container layer

    Why this is correct

    The topmost writable container layer, also called the 'container layer' or 'upperdir' in overlayfs terms, is where all runtime modifications are recorded. When a container creates, deletes, or alters files, those changes are written here using copy-on-write, making it the primary location for malicious scripts planted during execution. This layer is ephemeral and typically destroyed with the container unless it is explicitly preserved via docker commit or docker export, so forensic collection must target this layer for runtime tampering.

  • ✗

    The volume mounted from the host

    Why it's wrong here

    A volume mounted from the host is not part of the image or the container's layered filesystem; it is a separate host-side directory (or named volume) injected into the container's path. Writes to a volume bypass the copy-on-write layer entirely and persist on the host, so they do not reside in any container layer. While an attacker could use a volume to store malicious payloads, that is an alternative persistence mechanism, not the default layer where runtime changes like script injection accumulate.

  • ✗

    The base image layer

    Why it's wrong here

    The base image layer is the bottommost read-only layer in a Docker image, typically containing the operating system and legitimate installed packages. Any runtime modifications—including malicious scripts—are never written to this immutable layer; instead, new writes go to the upper writable layer. Unless the attacker deliberately tampered with the image itself (a supply-chain attack), the base layer will remain unchanged during container execution, making it an unlikely location for evidence of runtime compromise.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.