CHFI · domain
Application, Email and Cloud Forensics
Practise Computer Hacking Forensic Investigator CHFI Application, Email and Cloud Forensics practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Application, Email and Cloud Forensics questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Application, Email and Cloud Forensics
Watch out for
Common Application, Email and Cloud Forensics exam traps
Question index
All Application, Email and Cloud Forensics questions (25)
Click any question to see the full explanation, or start a practice session above.
During an email forensics investigation, an analyst examines headers and sees `Received: from mail.evil.com (192.168.1.100) by mail.victim.com` followed by `DKIM-Signature: v=1; a=rsa-sha256; d=evil.com; s=selector; bh=...; h=...; b=...`. The email claims to be from support@paypal.com. Which finding is the strongest indicator of spoofing?
Medium2An analyst finds the following string in an IIS log: %3Cscript%3Ealert('XSS')%3C/script%3E. What does this indicate?
Easy3During a forensic investigation of a compromised web server, an analyst examines the Apache access log and finds the following entry: '192.168.1.10 - - [12/Oct/2024:13:45:22 +0000] "GET /index.php?id=1 UNION SELECT username, password FROM users-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. What type of attack is MOST likely indicated?
Medium4During a forensic investigation of a Google Cloud Platform (GCP) environment, an analyst reviews Audit Logs and sees a log entry with the method 'storage.objects.list' and a principal email 'attacker@gmail.com'. However, the identity is not from the organization's domain. What should the analyst conclude?
Hard5A security analyst notices repeated entries in an IIS log: 10.0.0.2, -, 05/Feb/2023:08:12:34 +0000, GET /../../windows/system32/config/sam, 404, 0, 532. Which TWO of the following attack types are indicated by this log entry?
Medium6An investigator is analyzing email headers and notices the following: The 'Received' headers show a path through multiple servers, the 'DKIM-Signature' domain matches the sender domain, and 'X-Originating-IP' is present. Which TWO pieces of information are MOST useful to trace the original sender's IP address? (Choose two.)
Medium7A Docker container is suspected of malicious activity. Which THREE data sources should the investigator collect for forensic analysis?
Medium8During an investigation of a web application breach, an analyst reviews IIS logs and finds numerous entries with status code '200' and URIs containing '?cmd=' followed by encoded strings. The analyst also notices that some requests have a 'User-Agent' string resembling 'Microsoft-CryptoAPI/10.0'. What is the MOST likely conclusion?
Hard9Which THREE of the following are common challenges specific to cloud forensics? (Select THREE)
Hard10An email forensic analyst receives a suspicious email and wants to trace its origin. Which email header field provides the most reliable information about the IP address of the sending SMTP server?
Easy11Which tool is specifically designed to analyze email headers, track the path of an email, and extract metadata such as originating IP and authentication results?
Easy12Which email header field is specifically used to verify that an email was not tampered with during transit and is signed by the sender's domain?
Easy13Which of the following is a unique challenge in cloud forensics compared to traditional digital forensics?
Easy14Which of the following email headers is used to verify the domain of the sending server and is commonly used for authentication to prevent spoofing?
Medium15An analyst examines the following Apache access log entry: 192.168.1.10 - - [10/Jan/2023:13:45:22 +0000] "GET /search.php?q=1%27%20UNION%20SELECT%201,2,3-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0". Which attack is MOST likely indicated?
Easy16An email forensic analyst receives a suspicious email and wants to verify the originating IP address. The analyst extracts the email headers and sees multiple 'Received' fields. Which 'Received' header should the analyst consider as the most trustworthy source of the sender's IP?
Medium17In an email header, which field typically contains the IP address of the original sending client?
Easy18In an AWS environment, a security analyst detects unusual API calls that created several IAM users with administrative privileges from an unfamiliar IP address. Which AWS service log should be examined first to identify the specific API calls and the IAM user that made them?
Medium19A forensic analyst is examining MySQL binary logs to identify a data exfiltration event. Which TWO fields are most critical for reconstructing the stolen data?
Medium20During a forensic analysis of a compromised web server, an investigator identifies the following log entries. Which THREE entries are the strongest indicators of a successful web shell upload? (Choose three.)
Hard21During a database forensic investigation, you need to review Microsoft SQL Server transaction logs to identify unauthorized data modifications. Which of the following SQL Server functions or commands is used to read the transaction log?
Medium22Which cloud service log is most appropriate for tracking API calls and resource changes in an AWS environment?
Easy23A forensic analyst is investigating a Docker container that was used to launch a network attack. The container has been stopped but not removed. Which action should the analyst take FIRST to preserve volatile evidence?
Hard24Which of the following email authentication protocols uses a digital signature to verify the sender's domain and that the email has not been tampered with?
Easy25Which Azure log source should an investigator query to identify who deleted a virtual machine and when?
MediumOther domains
All CHFI exam domains
Frequently asked questions
- What does the Application, Email and Cloud Forensics domain cover on the CHFI exam?
- Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
- How many questions are in this domain?
- This page lists all 25 Application, Email and Cloud Forensics questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Application, Email and Cloud Forensics questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.