CHFI Application, Email and Cloud Forensics Practice Question
A forensic investigator finds a suspicious file named `cmd.aspx` in the web root of a compromised IIS server. The file contains code that accepts command input via HTTP GET parameters and executes it on the server. What is the MOST likely classification of this file?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web shell
A file that accepts commands via HTTP and executes them on the server is a web shell. ASPX is a common extension for .NET web shells.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trojan horse
Why it's wrong here
A Trojan horse is a broad category of malware disguised as legitimate software, often delivered via social engineering or droppers. While a web shell can be spread using Trojan tactics, classifying the file merely as a Trojan is too generic and less actionable; the specific forensic artifact is a server-resident script that enables remote command execution, which is precisely a web shell.
- ✗
Cross-site scripting (XSS) exploit
Why it's wrong here
Cross-site scripting (XSS) works by injecting client-side JavaScript into web pages that execute in a victim's browser, typically to steal cookies or deface content. The suspicious file 'cmd' resides on the server and is invoked via HTTP to run server-side OS commands, which XSS cannot do because it does not place files on disk or achieve server-side execution. Thus, the artifact's location and function point to a web shell, not an XSS exploit.
- ✗
SQL injection payload
Why it's wrong here
SQL injection payloads are crafted query fragments embedded in input parameters or HTTP requests, designed to manipulate database operations rather than execute OS commands. They are transient network data, not persistent files stored on the server. Because 'cmd' is a file on the filesystem that receives HTTP requests to invoke system commands, it is a web shell, not an SQL injection payload.
- ✓
Web shell
Why this is correct
A web shell is a malicious script placed on a web server that accepts commands via HTTP parameters—often using names like 'cmd'—to execute system processes, upload/download files, or create reverse shells. It provides persistent remote command execution and is the precise classification for a file that appears to be a command execution handler on an infected web server. This matches the forensic finding exactly.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.