Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

An analyst identifies an unknown binary running on a Linux server. Which /proc filesystem entry would provide the command-line arguments used to start the process?

⚠ Common exam trap

EC-Council often tests the distinction between /proc/[pid]/cmdline (command-line arguments) and /proc/[pid]/environ (environment variables), as candidates frequently confuse the two when asked about process startup details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/proc/[pid]/cmdline

/proc/[pid]/cmdline contains the exact command-line arguments used to start the process, stored as null-separated strings. This allows an analyst to see how the binary was invoked, including any flags or parameters, which is critical for identifying malicious or suspicious behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /proc/[pid]/maps

    Why it's wrong here

    /proc/[pid]/maps describes the process's virtual memory layout: each row lists a mapped region's address range, permissions (r/w/x/p), offset, device, inode, and backing file. This is useful for analyzing memory regions or detecting injected libraries, but it contains no information about how the process was invoked or its command-line arguments. Therefore, it cannot reveal the unknown binary's command line.

  • ✗

    /proc/[pid]/status

    Why it's wrong here

    /proc/[pid]/status provides process metadata such as state (e.g., running, sleeping), PID, PPID, UID/GID, memory usage (VmRSS, VmSize), and context switches. It does include a 'Name' field derived from /proc/[pid]/comm, but that field is truncated to 15 characters and stores only the executable's base name, not the original argv arguments. Thus, it's insufficient for identifying the complete command line.

  • ✗

    /proc/[pid]/environ

    Why it's wrong here

    /proc/[pid]/environ exposes the process's initial environment block as a series of null-separated KEY=value entries, including variables like PATH or HOME. While environment variables can be inherited or explicitly set, they are distinct from command-line arguments and rarely contain the actual invocation string. Reading it could provide context about the process's runtime environment, but it will not directly yield the command line.

  • ✓

    /proc/[pid]/cmdline

    Why this is correct

    /proc/[pid]/cmdline is the correct source because it exposes the process's original argv array, exactly as passed to execve, with each argument separated by a null byte. This file is typically read with a tool like 'tr' or by replacing null bytes with spaces to reconstruct the full command line, including the executable path, options, and arguments. However, note that for kernel threads or zombie processes the file may appear empty.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.