CHFI Application, Email and Cloud Forensics Practice Question
An analyst discovers a suspicious file named 'cmd.aspx' in the uploads directory of an IIS web server. Analysis reveals the file contains code to execute system commands. What is this file most likely?
⚠ Common exam trap
EC-Council often tests the misconception that any .aspx file in an uploads directory is legitimate, but the key differentiator is the presence of code that executes system commands, which is unique to a web shell.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A web shell
A web shell is a malicious script uploaded to a web server (like IIS) that allows an attacker to execute arbitrary system commands through the web interface. The file 'cmd.aspx' is an ASP.NET page, and its ability to execute system commands is the hallmark of a web shell, often used for post-exploitation persistence and remote access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A log file
Why it's wrong here
Log files record events in text; they do not contain code that executes system commands, and IIS logs are not named cmd.aspx nor stored in upload directories. It tempts because logs commonly appear in web directories, but the executable content rules that out.
- ✗
A benign configuration file
Why it's wrong here
Configuration files hold settings, not code that executes system commands, and IIS configuration does not live in an uploads directory as cmd.aspx. It tempts because .config files are legitimate on IIS, but the executable content and naming contradict that.
- ✓
A web shell
Why this is correct
A file placed in a web-accessible upload directory that executes system commands is a web shell, giving the attacker remote command execution through HTTP requests. The .aspx extension confirms it runs under IIS via ASP.NET, matching the scenario's server.
- ✗
A backup of a legitimate page
Why it's wrong here
A backup of a legitimate page would not contain code executing system commands, and backups are not placed in upload directories under command-style names. It tempts because legitimate pages do get backed up, but the executable content and location here indicate a web shell.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.