Courseiva

CHFI · domain

Application, Email and Cloud Forensics

This domain covers forensic acquisition and analysis of application, email, and cloud evidence. Expect questions on email header fields that reveal true origin, cloud log sources like AWS CloudTrail and S3 access logs, jurisdictional and multi-tenancy challenges, and API-level attribution of user actions in cloud environments.

113 questions30 easy56 medium27 hard

Focused practice

Practice Application, Email and Cloud Forensics questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Application, Email and Cloud Forensics

A candidate must be able to select the right email headers for origin and the right cloud log for API attribution. The single most important thing is knowing that CloudTrail records API activity and the IAM principal, while email origin comes from Received and Return-Path.

Identifying originating IP and sender from Received and Return-Path headers

Using AWS CloudTrail to trace API calls and IAM identities

Recognizing multi-jurisdiction data storage as a legal challenge

Analyzing cloud service logs for resource deletion and configuration changes

Watch out for

Common Application, Email and Cloud Forensics exam traps

  • ▸Assuming the From header shows the true sender; it is easily spoofed and not reliable for origin.
  • ▸Confusing CloudTrail with S3 access logs or VPC Flow Logs when tracking API calls and IAM users.
  • ▸Overlooking that cloud data may reside in multiple legal jurisdictions, complicating subpoenas and preservation.

Question index

All Application, Email and Cloud Forensics questions (113)

Click any question to see the full explanation, or start a practice session above.

1

An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?

Medium
2

Which tool is specifically designed for parsing and analyzing email headers to trace the origin of an email and detect spoofing?

Easy
3

A security analyst reviews an Apache access log and finds the entry: '192.168.1.10 - - [10/Mar/2025:08:12:34 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 2345 "-" "Mozilla/5.0"'. Which attack is indicated?

Medium
4

During an email forensics investigation, an analyst examines headers and sees `Received: from mail.evil.com (192.168.1.100) by mail.victim.com` followed by `DKIM-Signature: v=1; a=rsa-sha256; d=evil.com; s=selector; bh=...; h=...; b=...`. The email claims to be from support@paypal.com. Which finding is the strongest indicator of spoofing?

Medium
5

An analyst discovers a suspicious file named 'cmd.aspx' in the web root of an IIS server. The file contains ASPX code that executes system commands. The IIS logs show a POST request to '/cmd.aspx' with a 200 status code. Which type of attack is indicated?

Hard
6

In the context of cloud forensics, what is the primary challenge associated with volatile evidence in Infrastructure as a Service (IaaS) environments?

Easy
7

An analyst finds the following string in an IIS log: %3Cscript%3Ealert('XSS')%3C/script%3E. What does this indicate?

Easy
8

During a forensic investigation of a compromised web server, an analyst examines the Apache access log and finds the following entry: '192.168.1.10 - - [12/Oct/2024:13:45:22 +0000] "GET /index.php?id=1 UNION SELECT username, password FROM users-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. What type of attack is MOST likely indicated?

Medium
9

During a forensic investigation of a Google Cloud Platform (GCP) environment, an analyst reviews Audit Logs and sees a log entry with the method 'storage.objects.list' and a principal email 'attacker@gmail.com'. However, the identity is not from the organization's domain. What should the analyst conclude?

Hard
10

Which of the following is a primary challenge in cloud forensics due to shared infrastructure?

Medium
11

A security analyst notices repeated entries in an IIS log: 10.0.0.2, -, 05/Feb/2023:08:12:34 +0000, GET /../../windows/system32/config/sam, 404, 0, 532. Which TWO of the following attack types are indicated by this log entry?

Medium
12

A forensic analyst is examining a Docker container that was used to launch a DDoS attack. Which layer of a Docker image is most likely to contain the attacker's malicious scripts?

Hard
13

During a forensic investigation of a compromised web server, you find the following entry in the IIS log: 192.168.2.50, -, 10/Jan/2023, 14:32:15, W3SVC1, WEB01, 192.168.2.10, 80, POST, /uploads/shell.aspx, 200, 0, 0, 513, 0, Mozilla/4.0. Which action should the investigator prioritize?

Medium
14

Which tool is specifically designed to analyze email headers and track the path of an email across multiple servers?

Easy
15

An analyst examining an Outlook PST file wants to recover deleted emails that are no longer visible in the Deleted Items folder. Which technique is MOST effective?

Medium
16

A security analyst is investigating a phishing email and notices the DKIM-Signature header is present but fails validation. Which TWO actions should the analyst take?

Medium
17

An investigator is analyzing email headers and notices the following: The 'Received' headers show a path through multiple servers, the 'DKIM-Signature' domain matches the sender domain, and 'X-Originating-IP' is present. Which TWO pieces of information are MOST useful to trace the original sender's IP address? (Choose two.)

Medium
18

A forensic analyst is examining Azure Activity Logs for signs of privilege escalation. Which TWO of the following activities would be MOST indicative of an attacker attempting to escalate privileges? (Choose two.)

Medium
19

A Docker container is suspected of malicious activity. Which THREE data sources should the investigator collect for forensic analysis?

Medium
20

During an investigation of a web application breach, an analyst reviews IIS logs and finds numerous entries with status code '200' and URIs containing '?cmd=' followed by encoded strings. The analyst also notices that some requests have a 'User-Agent' string resembling 'Microsoft-CryptoAPI/10.0'. What is the MOST likely conclusion?

Hard
21

Which THREE of the following are indicators of a webshell in web server logs? (Select THREE)

Medium
22

A security analyst reviews Apache access logs and finds the following entry: `192.168.1.10 - - [12/Jul/2024:10:15:30 -0400] "GET /search.php?q=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 5321 "-" "Mozilla/5.0"`. Which attack technique is most likely being attempted?

Medium
23

In email forensics, which TWO of the following headers are most useful for identifying the true origin of an email? (Select TWO.)

Medium
24

A forensic analyst is investigating a suspected data exfiltration from a MySQL database. Which log source would be MOST useful to identify the exact SQL queries executed, including SELECT statements that retrieved large volumes of data?

Hard
25

An analyst finds the following in an IIS log: 10.0.0.5, -, 02/15/2024, 14:23:56, GET /../../windows/system32/cmd.exe, 404, 0, 0, 0, Mozilla/4.0. Which attack technique does this log entry represent?

Medium
26

Which cloud service's audit logs would an investigator examine to identify who deleted a virtual machine in an Azure subscription?

Easy
27

In cloud forensics, one of the major challenges is that data may be stored in multiple jurisdictions with different legal requirements. This challenge is known as:

Easy
28

Which TWO of the following are common challenges specific to cloud forensics?

Easy
29

Which THREE of the following are common challenges specific to cloud forensics? (Select THREE)

Hard
30

An analyst discovers a suspicious file named 'cmd.aspx' in the uploads directory of an IIS web server. Analysis reveals the file contains code to execute system commands. What is this file most likely?

Medium
31

An email forensic analyst receives a suspicious email and wants to trace its origin. Which email header field provides the most reliable information about the IP address of the sending SMTP server?

Easy
32

A security analyst is investigating a containerized application running on a Docker host. The analyst needs to collect forensic evidence from a stopped container without starting it. Which of the following Docker commands should be used to export the container's filesystem as a tar archive?

Medium
33

A forensic investigator is analyzing a compromised web server. In the Apache access logs, the investigator finds the following request: 'GET /images/../../../etc/passwd HTTP/1.1' with a 200 status code. Which of the following is the MOST likely reason the server returned a 200 (OK) response?

Hard
34

A forensic investigator is examining a compromised Docker container on a Linux host. The investigator needs to collect volatile evidence from the running container before it is stopped. Which two actions should the investigator perform to capture the container's memory and running processes? (Choose two.)

Hard
35

A security analyst reviewing Apache access logs finds entries like: 192.168.1.10 - - [12/Jan/2023:15:23:11 +0000] "GET /search?q=1' OR '1'='1 HTTP/1.1" 200 5324. What attack is indicated?

Medium
36

A web server log shows the following request: 'GET /../../../../etc/passwd HTTP/1.1' with a 200 response code. The web server is running Apache on Linux. What attack has likely succeeded?

Medium
37

Which email header field is specifically used to verify that an email was not tampered with during transit and is signed by the sender's domain?

Easy
38

An investigator needs to parse and analyze a Microsoft Outlook personal folders file (.pst). Which tool is specifically designed for this purpose?

Easy
39

An email forensic investigator examines a suspicious email and notices the following header: Received: from mail.evil.com (192.168.1.100) by mail.company.com. The DKIM-Signature header fails verification. What does this indicate?

Medium
40

Which TWO of the following are valid email header fields that can be used to detect email spoofing? (Select 2)

Easy
41

Which email header field is MOST reliable for identifying the true origin of an email, assuming no header tampering occurred at the initial MTA?

Easy
42

Which of the following is a unique challenge in cloud forensics compared to traditional digital forensics?

Easy
43

During a cloud forensics investigation of an AWS environment, an analyst extracts CloudTrail logs and notices many events with the error code 'AccessDenied' for a specific IAM user attempting to list an S3 bucket. Which of the following is the most appropriate next step?

Medium
44

In an Azure environment, a forensic analyst needs to identify which user assigned a specific role to another user, leading to privilege escalation. Which Azure log should the analyst examine?

Medium
45

During a cloud forensic investigation, the analyst discovers that the suspect used AWS IAM credentials to launch unauthorized EC2 instances. The suspect claims the credentials were stolen. Which log would the analyst examine to determine the source IP address from which the credentials were used?

Hard
46

Which tool is commonly used to analyze email headers and trace the path of an email across servers by parsing 'Received' fields?

Easy
47

A GCP audit log shows a project owner granted 'iam.serviceAccountUser' role to a service account from a different project. Which TWO potential security implications should the investigator prioritize?

Hard
48

Which of the following email headers is used to verify the domain of the sending server and is commonly used for authentication to prevent spoofing?

Medium
49

An analyst examining Apache access logs finds the following entry: 192.168.1.10 - - [10/Oct/2023:13:55:36 -0400] "GET /search.php?q=1'%20OR%20'1'='1 HTTP/1.1" 200 5324 "-" "Mozilla/5.0". Which of the following attacks is MOST likely occurring?

Medium
50

In a Google Cloud Platform (GCP) environment, a forensic investigator needs to determine who deleted a Cloud Storage bucket and when. Which log type should be queried to obtain this information?

Hard
51

In Docker forensics, which of the following commands would you use to inspect the history of an image, including the commands that created each layer?

Medium
52

An analyst examines the following Apache access log entry: 192.168.1.10 - - [10/Jan/2023:13:45:22 +0000] "GET /search.php?q=1%27%20UNION%20SELECT%201,2,3-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0". Which attack is MOST likely indicated?

Easy
53

Which TWO of the following are indicators of a webshell on a web server? (Select TWO.)

Medium
54

Which email header field is used to verify that an email was sent by the authorized mail server for the domain and has not been tampered with, using cryptographic signatures?

Easy
55

An investigator is analyzing a compromised MySQL database server. To determine the exact time and content of a suspect data exfiltration query, which MySQL log should be examined first, assuming it is enabled?

Medium
56

Which TWO of the following are appropriate techniques for identifying a webshell on a compromised web server?

Medium
57

During a forensic investigation of a compromised web server, you find a file named 'cmd.aspx' in the uploads directory. The file contains: <%@ Page Language="C#" %><% Response.Write(System.Diagnostics.Process.Start("cmd.exe","/c "+Request.QueryString["cmd"])).StandardOutput.ReadToEnd(); %>. What is the most likely purpose of this file?

Hard
58

In an email header, an analyst notices the following: 'Received: from mail.attacker.com (192.168.2.100) by mail.victim.com (Postfix) with ESMTP id ABC123 for <user@victim.com>; ...'. The 'From' address appears as 'ceo@victim.com'. Which type of attack is most likely?

Hard
59

An email forensic analyst receives a suspicious email and examines the full headers. Which header field is the MOST reliable for determining the true originating IP address of the sender, assuming no spoofing of the header?

Easy
60

A cloud forensic investigator is examining AWS CloudTrail logs for signs of unauthorized access to an S3 bucket. Which of the following CloudTrail event names would indicate a successful attempt to list the objects in the bucket?

Medium
61

An IIS log entry shows: `2024-07-15 14:22:10 10.0.0.5 GET /../../windows/system32/cmd.exe 404 - Mozilla/5.0`. What attack technique does this log entry indicate?

Medium
62

A security analyst finds the following entry in the Apache access log: 10.0.0.5 - - [20/Jan/2023:08:12:44 +0000] "GET /../../../../etc/passwd HTTP/1.1" 404 345 "-" "curl/7.68.0". Which attack was attempted?

Medium
63

A forensic investigator needs to collect evidence from a Google Cloud Platform (GCP) environment. Which of the following GCP services provides audit logs for administrative activities and data access?

Medium
64

A forensic investigator finds a suspicious file named `cmd.aspx` in the web root of a compromised IIS server. The file contains code that accepts command input via HTTP GET parameters and executes it on the server. What is the MOST likely classification of this file?

Medium
65

A security analyst is reviewing Apache access logs and finds repeated requests to /index.php?id=1' OR '1'='1. Which type of attack is MOST likely being attempted?

Medium
66

Which TWO of the following are valid methods to collect logs from Docker containers for forensic analysis? (Select TWO)

Hard
67

A forensic analyst is investigating a MySQL database server breach. Which log is MOST useful for identifying a series of queries that exfiltrated data, assuming the attacker used a compromised application account?

Hard
68

An email forensic analyst receives a suspicious email and wants to verify the originating IP address. The analyst extracts the email headers and sees multiple 'Received' fields. Which 'Received' header should the analyst consider as the most trustworthy source of the sender's IP?

Medium
69

An incident responder is analyzing a compromised web server and finds a file named 'cmd.aspx' in the uploads directory. The file contains ASP.NET code that accepts commands via the 'cmd' parameter and executes them on the server. Which of the following best describes this artifact?

Hard
70

A security analyst is investigating a potential data breach in a GCP environment. The analyst reviews the GCP audit logs and finds the following events: (1) A service account was granted the 'roles/storage.objectAdmin' role on a storage bucket containing sensitive data, (2) The service account then listed objects in the bucket, (3) The service account downloaded several objects. Which THREE actions should the analyst take immediately?

Hard
71

In an email header, which field typically contains the IP address of the original sending client?

Easy
72

Which TWO of the following are indicators of a webshell attack found in web server logs? (Select TWO)

Easy
73

In MySQL forensics, which log file is most commonly used to detect unauthorized data exfiltration or changes to database records?

Medium
74

A forensic analyst is examining a Microsoft Outlook PST file as part of an email investigation. Which tool is specifically designed to parse and analyze PST files and extract email metadata?

Medium
75

Which tool is specifically designed to extract metadata from email messages, including tracking the route and identifying the originating IP address?

Medium
76

During a forensic investigation of a compromised web server, an analyst finds the following entry in the IIS access log: 192.168.1.5, -, 04/May/2024:14:23:11, GET /scripts/..%5c../windows/system32/cmd.exe, 200. What is the probable attack vector?

Hard
77

In database forensics, which type of log records every transaction (including INSERT, UPDATE, DELETE) and allows reconstruction of database changes over time?

Easy
78

An analyst is investigating a possible data exfiltration via email. The analyst notices that the email headers contain a DKIM-Signature field that is invalid. Which of the following does a failed DKIM check indicate?

Hard
79

Which TWO of the following are common indicators of a path traversal attack found in web server logs? (Select 2)

Medium
80

During a cloud forensics investigation, an analyst examines AWS CloudTrail logs and finds an event with "userIdentity":{"type":"AssumedRole","arn":"arn:aws:sts::123456789012:assumed-role/AdminRole/i-0abcd1234efgh5678"}. What does the 'i-0abcd1234efgh5678' portion most likely represent?

Hard
81

An incident responder is analyzing AWS CloudTrail logs to determine if an unauthorized user accessed an S3 bucket. Which of the following CloudTrail event fields should be examined to identify the IAM user or role that made the API call?

Medium
82

In email forensics, which artifact is stored in Outlook's Personal Folders (.pst) files and can be analyzed using tools like Aid4Mail or EmailTracker?

Easy
83

A forensic analyst is examining a Docker container image for malware. Which TWO techniques can help analyze the image layers?

Easy
84

Which tool is specifically designed to extract and analyze email metadata, including headers, from various email client formats such as PST and OST files?

Easy
85

An analyst reviews an Apache access log entry: '192.168.1.10 - - [10/Oct/2023:13:55:36 +0000] "GET /index.php?id=1%27%20OR%20%271%27%3D%271 HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. Which attack does this log entry most likely indicate?

Medium
86

In an AWS environment, a security analyst detects unusual API calls that created several IAM users with administrative privileges from an unfamiliar IP address. Which AWS service log should be examined first to identify the specific API calls and the IAM user that made them?

Medium
87

A forensic investigator is analyzing a cloud environment hosted on Amazon Web Services (AWS). A compromised EC2 instance was used to exfiltrate data to an external IP address. The investigator needs to determine which AWS API calls were made to modify security groups to allow outbound traffic to that IP. Which AWS service should the investigator use to obtain this information?

Medium
88

A forensic analyst is examining MySQL binary logs to identify a data exfiltration event. Which TWO fields are most critical for reconstructing the stolen data?

Medium
89

A security analyst reviews an Apache access log entry: 192.168.1.5 - - [10/Jan/2024:08:12:35 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 4321 "-" "Mozilla/5.0". What type of attack is MOST likely indicated?

Easy
90

While investigating a compromised web server, you discover a file named 'shell.php' in the web root. The file contains the following code: <?php system($_GET['cmd']); ?>. Which of the following best describes this file?

Hard
91

Which of the following is a primary challenge in cloud forensics due to the shared responsibility model?

Easy
92

During a forensic analysis of a compromised web server, an investigator identifies the following log entries. Which THREE entries are the strongest indicators of a successful web shell upload? (Choose three.)

Hard
93

Which THREE of the following are challenges specific to container forensics? (Select THREE.)

Hard
94

A forensic analyst is examining a Google Cloud Platform (GCP) environment after a security incident. Which TWO GCP services should the analyst use to audit API activity and resource changes? (Select TWO.)

Medium
95

A forensic analyst is investigating a compromised Microsoft Exchange Server 2019. The attacker gained access to a mailbox and exfiltrated emails. The analyst needs to determine the exact time and IP address from which the attacker accessed the mailbox via Outlook Web App (OWA). Which Exchange log should the analyst examine to find this information?

Hard
96

A cloud forensic investigator is analyzing a GCP audit log entry for a Compute Engine instance. Which THREE fields are essential for identifying the user and operation performed?

Hard
97

Which TWO of the following are common challenges specific to cloud forensics? (Select TWO)

Medium
98

Which of the following tools is specifically designed to analyze email headers and track the path of an email, providing information about delays and potential spoofing?

Easy
99

During a database forensic investigation, you need to review Microsoft SQL Server transaction logs to identify unauthorized data modifications. Which of the following SQL Server functions or commands is used to read the transaction log?

Medium
100

In cloud forensics, which AWS service logs API calls for governance, compliance, and operational auditing, and is the primary source for detecting unauthorized access?

Medium
101

Which cloud service log is most appropriate for tracking API calls and resource changes in an AWS environment?

Easy
102

During an investigation of a suspected data exfiltration, a forensic analyst examines MySQL general query logs and finds a large number of SELECT queries retrieving customer records, followed by DELETE queries. Which of the following is the most likely conclusion?

Medium
103

A cloud forensics investigator is analyzing an incident in AWS. The suspect is alleged to have deleted an S3 bucket. Which AWS service log would contain the DeleteBucket API call details, including the source IP and user identity?

Medium
104

Which THREE of the following are challenges specific to container forensics?

Hard
105

A security analyst is reviewing Apache access logs and finds the entry: 192.168.1.100 - - [10/Mar/2025:08:12:34 +0000] "GET /search?q=test' OR '1'='1 HTTP/1.1" 200 532. Which attack does this log entry most likely indicate?

Easy
106

A forensic analyst is investigating a Docker container that was used to launch a network attack. The container has been stopped but not removed. Which action should the analyst take FIRST to preserve volatile evidence?

Hard
107

An organization uses Azure. A security analyst needs to investigate a suspicious login event. Which Azure log contains details about user sign-ins, including IP address, timestamp, and success/failure status?

Medium
108

Which cloud forensic challenge refers to the inability to physically access the storage media where data resides?

Easy
109

In cloud forensics, which AWS service provides a centralized log of API calls made by users and services, often used to investigate unauthorized access or configuration changes?

Medium
110

During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API call and the associated IAM user or role?

Medium
111

Which TWO pieces of information can be obtained from an email's Received headers to help trace the email's origin? (Select TWO)

Medium
112

Which of the following email authentication protocols uses a digital signature to verify the sender's domain and that the email has not been tampered with?

Easy
113

Which Azure log source should an investigator query to identify who deleted a virtual machine and when?

Medium

Frequently asked questions

What does the Application, Email and Cloud Forensics domain cover on the CHFI exam?
A candidate must be able to select the right email headers for origin and the right cloud log for API attribution. The single most important thing is knowing that CloudTrail records API activity and the IAM principal, while email origin comes from Received and Return-Path.
How many questions are in this domain?
This page lists all 113 Application, Email and Cloud Forensics questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Application, Email and Cloud Forensics questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-chfi EC-CHFI chfi app email cloud Practice Questions