Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

A security analyst is investigating a potential intrusion and finds a webshell on a Linux web server. Which of the following logs would be MOST useful to determine how the webshell was uploaded?

⚠ Common exam trap

EC-Council often tests the misconception that syslog or auth.log would capture web-based attacks, but the trap here is that candidates confuse system-level logs (auth, syslog, kern) with application-level logs (Apache access log), which are the only ones that record HTTP request details needed to trace a webshell upload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/var/log/apache2/access.log

The Apache access log (/var/log/apache2/access.log) records every HTTP request made to the web server, including the method (e.g., POST), URI, source IP, and user-agent. A webshell is typically uploaded via a file upload vulnerability or a crafted HTTP request (e.g., PUT or POST with multipart/form-data), so the access log will show the exact request that transferred the malicious file to the server, making it the most useful for determining the upload vector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /var/log/syslog

    Why it's wrong here

    /var/log/syslog records general system events via the syslog/rsyslog daemon, including service start/stop messages and kernel alerts, but it is not the destination for web server request logs. Apache handles HTTP traffic in user space and writes each request to its own dedicated logs, not to the syslog facility. Therefore, while syslog may show the Apache service starting or crashing, it will not contain details of POST requests or file uploads.

  • ✓

    /var/log/apache2/access.log

    Why this is correct

    /var/log/apache2/access.log is the canonical location for Apache web server request logging, typically using the combined log format to capture source IP, timestamp, HTTP method, URI, response status, user agent, and request bytes. A file upload manifests as a POST request to a specific endpoint, often with a large request size, and the access log provides the definitive timeline and source information needed for intrusion analysis. This log is the first stop for correlating suspicious upload activity with a specific client and session.

  • ✗

    /var/log/auth.log

    Why it's wrong here

    /var/log/auth.log is dedicated to authentication mechanisms such as PAM, SSH logins, and sudo commands, recording successful and failed attempts to authenticate against the host system. While a web application might authenticate users within the application itself, that does not generate entries in auth.log because Apache does not write application-level authentication events there. Thus, this log could reveal an attacker's lateral movement or credential brute force, but it will not show the pathway or contents of a web file upload.

  • ✗

    /var/log/kern.log

    Why it's wrong here

    /var/log/kern.log captures kernel-level events from the ring buffer, including device driver messages, memory allocation failures, and system call interruptions, which are wholly unrelated to application-layer HTTP transactions. Web requests are processed by Apache in user space and never traverse the kernel's logging path for application data. As a result, kern.log is only useful for ruling out hardware or kernel-level compromise; it cannot identify the requested URI, upload payload, or any application-layer anomaly.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.