CHFI Application, Email and Cloud Forensics Practice Question
A forensic analyst is examining Azure Activity Logs for signs of privilege escalation. Which TWO of the following activities would be MOST indicative of an attacker attempting to escalate privileges? (Choose two.)
⚠ Common exam trap
EC-Council often tests the distinction between actions that are destructive (like deleting a resource group) versus actions that actually elevate privilege levels (like creating a custom role or adding a user to a high-privilege directory role).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creation of a custom RBAC role with Owner permissions
Option C is correct because creating a custom RBAC role that includes Owner-level permissions (for example, wildcard actions like "*" or "Microsoft.Authorization/*/write") is a classic privilege-escalation technique — the attacker grants themselves or an accomplice full control over a scope without using a built-in role, which is exactly the kind of activity a forensic analyst should flag. Option D is correct because adding a user to the Global Administrator role is a direct, high-impact elevation to the highest privileged directory role in Microsoft Entra ID, granting full control over all Azure subscriptions and tenant resources, and is one of the most reliable indicators of attempted privilege escalation. Option A is not indicative because users changing their own password is a routine self-service action that does not change their authorization level. Option B is not indicative because deleting a resource group is a destructive/impact action, not an escalation of privileges. Option E is not indicative because accessing a storage account the user already owns is normal, authorized activity within their existing permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A user updating their own password
Why it's wrong here
A user changing their own password is routine self-service activity and does not alter role assignments or directory permissions. It is tempting because credential changes often accompany account takeover, and would be correct where the log shows a password reset performed against another user's account without authorisation.
- ✗
Deleting a resource group
Why it's wrong here
Deleting a resource group is destructive cleanup or anti-forensic activity, not privilege escalation; it grants no new role assignments or permissions. It is tempting because it is a high-impact, high-privilege operation, and would be relevant when investigating data destruction or impact rather than escalation.
- ✓
Creation of a custom RBAC role with Owner permissions
Why this is correct
Creating a custom RBAC role with Owner permissions lets an attacker define a bespoke role carrying full control, bypassing detection tuned to built-in role assignments. The Activity Log records the role definition write, revealing deliberate privilege escalation rather than legitimate administrative change.
- ✓
Adding a user to the Global Administrator role
Why this is correct
Adding a user to the Global Administrator role grants unrestricted tenant-wide control, the highest privilege escalation possible. Azure Activity Logs record this as a role assignment operation, making it a direct indicator that an attacker is elevating from limited access to full administrative authority over the subscription.
- ✗
A user accessing a storage account they own
Why it's wrong here
Accessing a storage account the user already owns exercises existing permissions and creates no new role assignment. It is tempting because storage access can indicate data exfiltration, and would be correct when investigating collection or staging rather than privilege escalation.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.