Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A network forensic analyst examines a pcap file in Wireshark and sees an HTTP POST request to '/shell.jsp' with a parameter 'cmd' containing 'dir'. The response contains a directory listing. Which intrusion artifact is indicated?

⚠ Common exam trap

Many exam-takers confuse the directory listing output with directory traversal (Option B), but directory traversal reads files via path manipulation, not by executing a command like 'dir' through a server-side script parameter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Webshell

The HTTP POST request to '/shell.jsp' with a 'cmd' parameter containing 'dir' and a response showing a directory listing is a classic indicator of a webshell. A webshell is a malicious script (e.g., JSP, ASP, PHP) uploaded to a web server that allows an attacker to execute arbitrary system commands via HTTP requests, effectively providing remote command execution. The presence of a command parameter and the server's response executing that command directly confirms the artifact is a webshell.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection exploits improperly sanitized input to alter SQL queries executed by the database, typically using tokens like UNION or single quotes, and yields database records, not operating system file listings. The pcap's 'cmd' parameter and resulting directory listing are characteristic of server-side command execution, which SQL injection cannot directly produce unless chained with xp_cmdshell or a similar database-specific feature, an unlikely and indirect mechanism. Therefore, this traffic pattern does not match classic SQL injection.

  • ✗

    Directory traversal

    Why it's wrong here

    Directory traversal abuses unvalidated file paths, sending sequences like ../../../etc/passwd to make the application read arbitrary files from the filesystem, returning file contents—not a dynamic command result. A webshell scenario, by contrast, passes an OS command through a parameter such as 'cmd' and returns the command's execution output, such as a directory listing. The observed command parameter and listing are functional evidence of remote code execution, not merely path manipulation.

  • ✓

    Webshell

    Why this is correct

    A webshell is a server-side script (e.g., PHP or ASP) that accepts HTTP parameters such as 'cmd' and passes them to system functions like shell_exec(), allowing remote attackers to run arbitrary operating system commands. The pcap's 'cmd' parameter accompanied by a directory listing is the classic fingerprint of a webshell: the attacker issues ls/dir and the response contains the filesystem enumeration. This combination of HTTP request structure with observable command output directly matches webshell behavior.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting works by injecting JavaScript or HTML payloads that execute in the victim's browser, targeting other users or the session context, not the web server's operating system. The captured traffic shows the server executing a command and returning a directory listing, which requires server-side interpretation of the 'cmd' parameter—something XSS cannot achieve because it runs client-side only. Therefore, XSS is not a plausible classification for this pcap.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.