CHFI OS and Network Forensics Practice Question
A network forensic investigator is analyzing traffic from a compromised web server. Which TWO artifacts are MOST likely to indicate the presence of a web shell? (Select TWO.)
⚠ Common exam trap
In EC-CHFI, the focus is on identifying web shells through application-layer artifacts such as suspicious script files in web directories and unusual HTTP POST requests. Network-level anomalies like DNS queries or SYN floods are not as specific to web shells.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Presence of a suspicious .aspx or .php file in web directories
Option C is correct because web shells are typically deployed as malicious script files (e.g., .aspx, .php, .jsp) placed in web-accessible directories, so finding an unexpected or suspicious script file there is a strong indicator of a web shell. Option D is correct because web shells are commonly invoked through HTTP POST requests to unusual or non-standard script paths, allowing attackers to send commands and receive output over the web channel. Options A, B, and E are not the most likely indicators: DNS queries to external domains, excessive SYN-ACK packets, and high ICMP traffic can reflect other activities such as command-and-control, scanning, or tunneling, but they are not specific artifacts of a web shell on a compromised web server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Multiple DNS queries to external domains
Why it's wrong here
Multiple DNS queries to external domains can indicate DNS tunneling or command-and-control exfiltration, but web shells primarily communicate over HTTP/HTTPS to and from the compromised web server. A web shell itself does not generate DNS queries; rather, it receives commands via web requests. Therefore, while anomalous DNS may warrant investigation, it is not a specific or reliable indicator of a web shell on a web directory.
- ✗
Excessive SYN-ACK packets
Why it's wrong here
SYN-ACK packets are simply the second step of the TCP three-way handshake, generated when a server acknowledges a connection request. Web shell usage involves established HTTP sessions, not bulk SYN-ACK exchanges; an excess of such packets typically signals a SYN flood, port scanning, or network reconnaissance. Since normal web browsing and shell access both rely on completed handshakes, a high SYN-ACK count lacks diagnostic value for web shell detection.
- ✓
Presence of a suspicious .aspx or .php file in web directories
Why this is correct
A web shell is a server-side script that executes commands on the host, and attackers commonly upload it with an executable extension such as .php, .aspx, .jsp, or .cgi into a web-accessible directory. Uncovering an unexpected script file in the web root—especially one with recent creation time or placed in a writable uploads folder—is a direct file-system artifact of a web shell infection. This is the strongest and most specific indicator among the choices, as it represents the actual payload left behind by the attacker.
- ✓
Unusual HTTP POST requests to non-standard scripts
Why this is correct
Web shells typically accept attacker-supplied command strings through HTTP POST requests to a script; the POST body may contain encoded or obfuscated payloads such as cmd, powershell, or base64 strings. Observing POST requests to a script that is normally GET-only, or to a non-standard endpoint like /uploads/image.php, strongly suggests command execution via a backdoor. Such traffic deviates from the application's baseline behavior and is a robust network-level indicator of web shell activity.
- ✗
High volume of ICMP traffic
Why it's wrong here
Web shells operate over application-layer HTTP/HTTPS and do not generate ICMP packets by themselves; high volumes of ICMP echo/reply usually point to ping sweeps, Smurf attacks, or other network-layer scanning. While ICMP can theoretically be used as a covert channel, that is a separate and rare technique unrelated to typical web shell command flows. Thus, ICMP flooding is a general anomaly indicator, not a specific sign of a web shell on a web server.
Visual reference
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.