CHFI OS and Network Forensics Practice Question
A forensic investigator is examining a Linux system compromised via a web application. Which THREE artifacts should the investigator prioritize to determine the attacker's entry point and post-exploitation activities?
⚠ Common exam trap
EC-Council often tests the distinction between artifacts that record past events (logs, history) versus configuration files that define system behavior (shadow, crontab), leading candidates to mistakenly choose /etc/shadow or cron entries as forensic evidence of attacker actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/home/compromised_user/.bash_history
Option A, /home/compromised_user/.bash_history, is correct because the shell history file records the exact commands the attacker typed after gaining access, directly revealing post-exploitation activities such as reconnaissance, privilege escalation attempts, and persistence commands. Option C, /var/log/auth.log, is correct because it captures authentication events including sudo usage, su attempts, SSH logins, and PAM failures, which help establish how the attacker escalated privileges or moved laterally after the initial web compromise. Option E, web server access logs (e.g., /var/log/apache2/access.log), is correct because they record HTTP requests with source IPs, URIs, and status codes, allowing the investigator to identify the malicious request that exploited the web application and thus the entry point. Option B, /etc/shadow, is not a priority artifact here because it only stores password hashes and does not by itself show attacker activity or entry vectors. Option D, cron job entries in /etc/crontab, is not among the top three because while cron can indicate persistence, it is less directly tied to identifying the entry point and immediate post-exploitation actions than the history, auth, and access logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
/home/compromised_user/.bash_history
Why this is correct
Bash history is the strongest indicator of the attacker's hands-on-keyboard activity after an initial foothold is established, recording the exact commands typed into an interactive shell such as ssh. Because it contains a chronological command sequence, it can reveal what binaries were downloaded, permissions changed, persistence mechanisms planted, and data exfiltrated. Although a sophisticated attacker may clear or disable history, its presence in this scenario makes it the definitive artifact for reconstructing post-exploitation actions.
- ✗
/etc/shadow
Why it's wrong here
/etc/shadow stores each local account's password hash, typically based on SHA-512 or bcrypt, with per-account aging metadata and root-only read permission. While a leaked shadow file lets an investigator attempt offline password cracking to discover a valid credential or prove lateral movement capability, it contains no timestamps, source IPs, or command history. It therefore explains why an attacker might succeed later, but not the initial compromise vector or the activities performed.
- ✓
/var/log/auth.log
Why this is correct
auth.log, typically at /var/log/auth.log on Debian/Ubuntu systems and /var/log/secure on RHEL derivatives, captures sshd, sudo, su, and PAM authentication events with timestamps, usernames, and remote IP addresses. An unusually high count of failed root logins followed by one successful session indicates a brute-force entry, while a single successful login from an unexpected foreign IP suggests valid credential abuse. This log directly reveals the entry point and is therefore a correct artifact for the investigation footprint.
- ✗
Cron job entries in /etc/crontab
Why it's wrong here
Cron entries in /etc/crontab and /etc/cron.* directories are a common persistence technique: the attacker adds a scheduled task to reconnect, execute a beacon, or reinstall a backdoor at regular intervals, often as root. While this is a valid indicator of post-compromise persistence, it is not an initial entry vector and contains no commands typed by the attacker before persistence was installed. It answers the question 'How do they stay in?' rather than 'How did they get in and what did they do?'
- ✓
Web server access logs (e.g., /var/log/apache2/access.log)
Why this is correct
If the compromised Linux system is running a public web service, the Apache or Nginx access log enumerates every HTTP request method, path, query string, status code, user agent, and client IP. These entries can capture the exact exploitation request — for example, a PHP file inclusion, SQL injection, or web shell upload — that transitioned the attacker from network access to code execution. The log is service-specific, however, and must be paired with error logs and system authentication logs to see whether an exploit succeeded, which is why it is a correct but not standalone source for the entry attack.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.