CHFI OS and Network Forensics Practice Question
A security analyst is investigating a potential intrusion and finds a webshell on a Linux web server. Which of the following logs would be MOST useful to determine how the webshell was uploaded?
⚠ Common exam trap
EC-Council often tests the misconception that syslog or auth.log would capture web-based attacks, but the trap here is that candidates confuse system-level logs (auth, syslog, kern) with application-level logs (Apache access log), which are the only ones that record HTTP request details needed to trace a webshell upload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/log/apache2/access.log
The Apache access log (/var/log/apache2/access.log) records every HTTP request made to the web server, including the method (e.g., POST), URI, source IP, and user-agent. A webshell is typically uploaded via a file upload vulnerability or a crafted HTTP request (e.g., PUT or POST with multipart/form-data), so the access log will show the exact request that transferred the malicious file to the server, making it the most useful for determining the upload vector.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/var/log/syslog
Why it's wrong here
/var/log/syslog records general system events via the syslog/rsyslog daemon, including service start/stop messages and kernel alerts, but it is not the destination for web server request logs. Apache handles HTTP traffic in user space and writes each request to its own dedicated logs, not to the syslog facility. Therefore, while syslog may show the Apache service starting or crashing, it will not contain details of POST requests or file uploads.
- ✓
/var/log/apache2/access.log
Why this is correct
/var/log/apache2/access.log is the canonical location for Apache web server request logging, typically using the combined log format to capture source IP, timestamp, HTTP method, URI, response status, user agent, and request bytes. A file upload manifests as a POST request to a specific endpoint, often with a large request size, and the access log provides the definitive timeline and source information needed for intrusion analysis. This log is the first stop for correlating suspicious upload activity with a specific client and session.
- ✗
/var/log/auth.log
Why it's wrong here
/var/log/auth.log is dedicated to authentication mechanisms such as PAM, SSH logins, and sudo commands, recording successful and failed attempts to authenticate against the host system. While a web application might authenticate users within the application itself, that does not generate entries in auth.log because Apache does not write application-level authentication events there. Thus, this log could reveal an attacker's lateral movement or credential brute force, but it will not show the pathway or contents of a web file upload.
- ✗
/var/log/kern.log
Why it's wrong here
/var/log/kern.log captures kernel-level events from the ring buffer, including device driver messages, memory allocation failures, and system call interruptions, which are wholly unrelated to application-layer HTTP transactions. Web requests are processed by Apache in user space and never traverse the kernel's logging path for application data. As a result, kern.log is only useful for ruling out hardware or kernel-level compromise; it cannot identify the requested URI, upload payload, or any application-layer anomaly.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.