CHFI OS and Network Forensics Practice Question
A forensic examiner is analyzing a Linux system suspected of being used as a C2 server. Which THREE artifacts should the examiner prioritize to find evidence of command execution and persistence? (Select three.)
⚠ Common exam trap
EC-ChFI often tests the distinction between logs that record authentication events (auth.log) versus logs that record command execution (bash_history), and candidates may mistakenly choose syslog thinking it captures all system activity, but it does not reliably capture per-user shell commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
~/.bash_history
Option A, ~/.bash_history, is correct because it records the interactive commands executed by a user's Bash shell, which can reveal attacker commands used to establish or operate C2 functionality. Option D, /var/log/auth.log, is correct because on Debian-based Linux systems it captures authentication events such as SSH logins, sudo usage, and failed login attempts, which help trace unauthorized access and privilege escalation tied to persistence. Option E, /etc/crontab, is correct because it is a system-wide cron table where scheduled jobs can be added by attackers to maintain persistence and periodically re-execute malicious commands. Option B, /var/log/syslog, is not among the marked answers because although it contains general system messages, it is less directly focused on command execution and persistence than the selected artifacts. Option C, /etc/passwd, is not among the marked answers because it primarily lists local user accounts and does not by itself provide evidence of command execution or persistence mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
~/.bash_history
Why this is correct
~/.bash_history records commands typed in interactive Bash sessions, revealing executed tooling, downloaded payloads and reconnaissance. This satisfies the stem's command execution and persistence constraint, since it directly evidences what the operator ran on the suspected C2 host.
- ✗
/var/log/syslog
Why it's wrong here
/var/log/syslog records general system and service messages, not the shell history or scheduled-task changes that evidence command execution and persistence. It tempts because syslog is a standard Linux log, yet the examiner needs bash history, cron entries and systemd unit files for this scenario.
- ✗
/etc/passwd
Why it's wrong here
/etc/passwd lists local accounts and shells, not command execution or persistence mechanisms, so it cannot evidence C2 activity. It is tempting because account auditing is standard practice, and it would be the right artefact when hunting rogue or unauthorised user accounts rather than executed commands.
- ✓
/var/log/auth.log
Why this is correct
/var/log/auth.log records authentication events, sudo invocations and session openings, so it evidences interactive command execution and privilege escalation on the suspected C2 host. It satisfies the command-execution artefact requirement, complementing persistence-focused files rather than replacing them.
- ✓
/etc/crontab
Why this is correct
/etc/crontab reveals scheduled commands, directly satisfying the persistence requirement: attackers add entries here to re-execute payloads after reboot or at fixed intervals. Unlike user crontabs, it includes a user field, so it also exposes which account executes the malicious job, tying persistence to command execution evidence.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.