Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

An analyst discovers a suspicious file named 'cmd.aspx' in the web root of an IIS server. The file contains ASPX code that executes system commands. The IIS logs show a POST request to '/cmd.aspx' with a 200 status code. Which type of attack is indicated?

⚠ Common exam trap

In CHFI, candidates often confuse webshell upload with directory traversal, mistakenly thinking the POST request to an existing file indicates traversal rather than recognizing the uploaded executable payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Webshell upload

The presence of a file named 'cmd.aspx' in the IIS web root that executes system commands, combined with a POST request returning a 200 status code, indicates a webshell upload attack. An attacker has uploaded an ASPX file that acts as a backdoor, allowing remote command execution via HTTP POST requests, which is a classic webshell scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Webshell upload

    Why this is correct

    The .aspx extension indicates an ASP.NET server-side script that executes within the IIS worker process. A file named cmd.aspx typically contains C# code that calls System.Diagnostics.Process to spawn system commands, effectively giving an attacker interactive command-line access over HTTP. Its presence in the web root without a correlated legitimate upload points to an uploaded webshell, not an attack that injects ephemeral code or manipulates path parameters.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection arises when unsanitized input alters the structure of an SQL query, allowing unauthorized database access or manipulation, and in some configurations may even write data via database-specific file I/O. It does not, by itself, produce a standalone executable .aspx file in the web tree; any file created as a side effect would be a database artifact, not a generic command shell. The observed cmd.aspx artifact is a direct file upload, so the root cause is not query injection.

  • ✗

    Cross-site scripting (XSS)

    Why it's wrong here

    Cross-site scripting (XSS) relies on injecting client-side JavaScript or HTML that executes in a victim's browser, typically to steal credentials, hijack sessions, or deface pages. Because it runs in the browser, XSS cannot execute system commands on the web server, and it produces no server-side executable file. A .aspx file is server-run code controlling the HTTP response, which places it in a completely different category than a stored or reflected XSS payload.

  • ✗

    Directory traversal

    Why it's wrong here

    Directory traversal (path traversal) exploits poor validation of file paths to read files outside the intended web root, such as web.config or /etc/passwd, using sequences like ../ and encoded variants. This flaw is read-oriented and does not create a new file on the server. Even if chained with a write primitive, the attacker still needs an upload mechanism to place cmd.aspx; the defining indicator here is an uploaded executable script, not manipulation of path traversal parameters.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.