CHFI Application, Email and Cloud Forensics Practice Question
A security analyst is investigating a containerized application running on a Docker host. The analyst needs to collect forensic evidence from a stopped container without starting it. Which of the following Docker commands should be used to export the container's filesystem as a tar archive?
⚠ Common exam trap
Watch out — candidates often confuse `docker export` (container filesystem to tar) with `docker save` (image layers to tar), as both produce tar archives but target different objects (container vs. image).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
docker export
The `docker export` command creates a tar archive of a container's filesystem, even if the container is stopped, without starting it. This is the correct tool for extracting forensic evidence from a stopped container's filesystem as a single archive file.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
docker commit
Why it's wrong here
docker commit is for creating a new image from a container's current state, capturing the writable layer on top of the base image as a new image in the local image store. It preserves image metadata, history, and configuration, so the result is still a Docker image, not a flat filesystem archive. Unlike docker export, it does not produce a standalone tar of the container's filesystem and requires docker load or a registry push to move it elsewhere.
- ✓
docker export
Why this is correct
docker export is the correct command because it streams the container's entire filesystem into a flat tar archive, exactly the kind of backup or migration artifact the analyst would need. It captures the full root filesystem as the container sees it, including all runtime changes, but intentionally omits image metadata and layer history. This tar can be piped to a file or imported later with docker import to reconstruct a filesystem as an image.
- ✗
docker cp
Why it's wrong here
docker cp copies individual files or directories between a container and the host filesystem using the container:path syntax. It is designed for selective file retrieval or injection, not for producing a complete snapshot of the container's filesystem. Even if you copy the entire root directory, the output is a copied directory tree, not a single portable tar archive, and it may not preserve every filesystem attribute such as hard links or extended metadata the way export does.
- ✗
docker save
Why it's wrong here
docker save serializes a Docker image into a tar archive, including all its layers, tags, and image configuration, for use with docker load. It operates on an image name or ID, not on a running or stopped container, so any changes stored in the container's writable layer are absent from the saved artifact. To capture runtime modifications, you would first need docker commit to freeze the container as a new image, whereas docker export directly gives you the modified filesystem.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.