Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A forensic investigator is examining a compromised Docker container on a Linux host. The investigator needs to collect volatile evidence from the running container before it is stopped. Which two actions should the investigator perform to capture the container's memory and running processes? (Choose two.)

⚠ Common exam trap

The trap here is assuming that copying /proc or reading logs captures memory, when these methods only provide partial or non-volatile data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use 'docker checkpoint' to create a checkpoint of the running container, including its memory state

To capture volatile evidence from a running Docker container, the investigator should list running processes and capture memory state. Running 'ps aux' inside the container provides a snapshot of active processes, while 'docker checkpoint' preserves the container's memory and state. Other options like copying /proc, reading logs, or checking filesystem diffs do not capture memory or process information reliably.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run 'docker logs <container_id>' to capture the container's stdout and stderr output

    Why it's wrong here

    Docker logs capture the standard output and standard error of the container's main process, which may include application logs. However, they do not provide memory contents or a list of running processes. While useful for understanding application behavior, they are not volatile evidence of memory or processes, so they do not meet the requirement.

  • ✗

    Use 'docker diff <container_id>' to list changes to the container's filesystem

    Why it's wrong here

    Docker diff shows changes to the container's filesystem compared to its base image, such as added, modified, or deleted files. It does not capture memory or running processes. This is useful for identifying file system modifications but is not volatile evidence of memory or active processes, so it is not a correct action for this scenario.

  • ✓

    Use 'docker checkpoint' to create a checkpoint of the running container, including its memory state

    Why this is correct

    Docker checkpoint (using CRIU) captures the entire state of a running container, including memory, CPU registers, and open files, and saves it to disk. This allows the investigator to preserve volatile memory for later analysis without stopping the container. It is a valid method for capturing memory evidence from a running container.

  • ✓

    Run 'docker exec -it <container_id> ps aux' to list running processes inside the container

    Why this is correct

    Executing 'ps aux' inside the container via docker exec captures the list of running processes at that moment. This is volatile evidence that would be lost if the container is stopped or restarted. It provides insight into malicious processes, their PIDs, and resource usage, which is essential for forensic analysis.

  • ✗

    Use 'docker cp' to copy the container's /proc directory to the host for analysis

    Why it's wrong here

    The /proc directory is a pseudo-filesystem that reflects the current state of the kernel and processes. Copying it with docker cp would not capture a consistent snapshot; it would copy files that may change during the copy, leading to incomplete or inaccurate data. Moreover, /proc contains live kernel data that is not fully represented as regular files. Thus, this is not a reliable method for volatile evidence collection.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.