Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A forensic investigator is analyzing a compromised web server. In the Apache access logs, the investigator finds the following request: 'GET /images/../../../etc/passwd HTTP/1.1' with a 200 status code. Which of the following is the MOST likely reason the server returned a 200 (OK) response?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server is vulnerable to directory traversal and returned the contents of /etc/passwd

A 200 response to a path traversal request indicates that the server executed the request and returned the file content, meaning the directory traversal attack succeeded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server redirected the request to the root directory and returned the index page

    Why it's wrong here

    An HTTP redirect is implemented via 3xx status codes such as 301, 302, or 307, so a redirected request cannot produce a 200 OK for the original URL. If the server had redirected the traversal payload to the root directory, the client would first receive a 3xx response, and only after following that redirect would it receive a 200 for the index page. The question indicates a 200 response to the traversal request itself, which a redirect cannot explain. Moreover, typical directory traversal exploitation does not trigger redirects; the server directly serves the requested file.

  • ✗

    The server has a custom 404 page that returns a 200 status code

    Why it's wrong here

    While some misconfigured web servers do return a 200 status code for custom 404 error pages, this option fails to account for the response body containing the targeted file, such as /etc/passwd. A custom 404 page would return a predefined HTML error page, not the contents of an arbitrary file referenced in the URL. Even if the server incorrectly labels not-found pages as 200, the response would not include the traversal target's data unless the server is also vulnerable and actually processed the traversal. Thus, a 200 status alone is not enough; the body must match the requested file, which points to traversal, not a custom error page.

  • ✗

    The request was blocked by a web application firewall (WAF) which returned a 200 status

    Why it's wrong here

    Web application firewalls (WAFs) typically block malicious requests by returning HTTP error status codes like 403 Forbidden or 406 Not Acceptable, or by dropping the connection entirely; a 200 OK response indicates the request passed the WAF and was processed by the application. If a WAF intercepted the request, it would not serve the contents of /etc/passwd; instead, it would return a block notification or error page. The presence of a 200 with file content means the request reached the backend server, which then exploited the traversal. Therefore, a WAF response cannot explain the observed behavior without contradicting standard WAF semantics.

  • ✓

    The server is vulnerable to directory traversal and returned the contents of /etc/passwd

    Why this is correct

    A 200 OK status in response to a directory traversal payload—such as a URL containing ../../etc/passwd—strongly indicates that the server successfully accessed and returned the specified file. In a vulnerable web server, improper path sanitization allows the attacker to escape the web root and retrieve sensitive system files, with the response body containing the file's contents (e.g., root:x:0:0:root:/root:/bin/bash). This is the classic signature of a path traversal vulnerability, as the server processes the '../' sequences and serves the requested file. The combination of the traversal payload and a 200 status, along with the file content in the response, confirms successful exploitation.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.