Courseiva
OS and Network Forensics →easyMultiple Select

CHFI OS and Network Forensics Practice Question

A network forensic investigator is analyzing traffic from a compromised web server. Which TWO artifacts are MOST likely to indicate the presence of a web shell? (Select TWO.)

⚠ Common exam trap

In EC-CHFI, the focus is on identifying web shells through application-layer artifacts such as suspicious script files in web directories and unusual HTTP POST requests. Network-level anomalies like DNS queries or SYN floods are not as specific to web shells.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Presence of a suspicious .aspx or .php file in web directories

Option C is correct because web shells are typically deployed as malicious script files (e.g., .aspx, .php, .jsp) placed in web-accessible directories, so finding an unexpected or suspicious script file there is a strong indicator of a web shell. Option D is correct because web shells are commonly invoked through HTTP POST requests to unusual or non-standard script paths, allowing attackers to send commands and receive output over the web channel. Options A, B, and E are not the most likely indicators: DNS queries to external domains, excessive SYN-ACK packets, and high ICMP traffic can reflect other activities such as command-and-control, scanning, or tunneling, but they are not specific artifacts of a web shell on a compromised web server.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multiple DNS queries to external domains

    Why it's wrong here

    Multiple DNS queries to external domains can indicate DNS tunneling or command-and-control exfiltration, but web shells primarily communicate over HTTP/HTTPS to and from the compromised web server. A web shell itself does not generate DNS queries; rather, it receives commands via web requests. Therefore, while anomalous DNS may warrant investigation, it is not a specific or reliable indicator of a web shell on a web directory.

  • ✗

    Excessive SYN-ACK packets

    Why it's wrong here

    SYN-ACK packets are simply the second step of the TCP three-way handshake, generated when a server acknowledges a connection request. Web shell usage involves established HTTP sessions, not bulk SYN-ACK exchanges; an excess of such packets typically signals a SYN flood, port scanning, or network reconnaissance. Since normal web browsing and shell access both rely on completed handshakes, a high SYN-ACK count lacks diagnostic value for web shell detection.

  • ✓

    Presence of a suspicious .aspx or .php file in web directories

    Why this is correct

    A web shell is a server-side script that executes commands on the host, and attackers commonly upload it with an executable extension such as .php, .aspx, .jsp, or .cgi into a web-accessible directory. Uncovering an unexpected script file in the web root—especially one with recent creation time or placed in a writable uploads folder—is a direct file-system artifact of a web shell infection. This is the strongest and most specific indicator among the choices, as it represents the actual payload left behind by the attacker.

  • ✓

    Unusual HTTP POST requests to non-standard scripts

    Why this is correct

    Web shells typically accept attacker-supplied command strings through HTTP POST requests to a script; the POST body may contain encoded or obfuscated payloads such as cmd, powershell, or base64 strings. Observing POST requests to a script that is normally GET-only, or to a non-standard endpoint like /uploads/image.php, strongly suggests command execution via a backdoor. Such traffic deviates from the application's baseline behavior and is a robust network-level indicator of web shell activity.

  • ✗

    High volume of ICMP traffic

    Why it's wrong here

    Web shells operate over application-layer HTTP/HTTPS and do not generate ICMP packets by themselves; high volumes of ICMP echo/reply usually point to ping sweeps, Smurf attacks, or other network-layer scanning. While ICMP can theoretically be used as a covert channel, that is a separate and rare technique unrelated to typical web shell command flows. Thus, ICMP flooding is a general anomaly indicator, not a specific sign of a web shell on a web server.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.