Courseiva

CCNA Application, Email and Cloud Forensics Questions

38 of 113 questions · Page 2/2 · Application, Email and Cloud Forensics · Answers revealed

76
MCQhard

During a forensic investigation of a compromised web server, an analyst finds the following entry in the IIS access log: 192.168.1.5, -, 04/May/2024:14:23:11, GET /scripts/..%5c../windows/system32/cmd.exe, 200. What is the probable attack vector?

A.Brute force attack
B.Cross-site scripting
C.Path traversal
D.SQL injection
AnswerC

The ..%5c.. sequence is URL encoding where %5c represents a backslash, so the payload decodes to ..\.., the classic directory-traversal prefix used to escape the web root. When processed by a vulnerable IIS server, this allowed an attacker to request files like C:\windows\system32\cmd.exe with the unencoded traversal string intact. The request is a single crafted path with encoded separators, which is precisely the signature of a path traversal attack rather than any of the other categories listed.

Why this answer

The log shows a path traversal attempt using URL-encoded backslashes (%5c) to navigate to cmd.exe. The 200 status indicates the request succeeded. This is a classic path traversal attack.

77
MCQeasy

In database forensics, which type of log records every transaction (including INSERT, UPDATE, DELETE) and allows reconstruction of database changes over time?

A.Audit log
B.Error log
C.Transaction log
D.Slow query log
AnswerC

The transaction log (also known as the redo log or write-ahead log) is the authoritative database component that sequentially records every data modification operation before it is committed to the main data files. In crash recovery, this log ensures ACID durability by enabling rollback of uncommitted transactions and replay of committed ones. Because it captures the before-and-after images (or logical changes) of all successful and incomplete transactions, it is the correct answer for a log that records every transaction.

Why this answer

Transaction logs (also called redo logs) record all changes to the database, enabling point-in-time recovery and auditing of data modifications.

78
MCQhard

An analyst is investigating a possible data exfiltration via email. The analyst notices that the email headers contain a DKIM-Signature field that is invalid. Which of the following does a failed DKIM check indicate?

A.The email's content has been modified since it was signed
B.The email was sent through a proxy server
C.The email client does not support DKIM
D.The email was sent from a different domain than the one in the From field
AnswerA

DKIM signs specific header fields and the message body with a private key; verification uses the public key in DNS. A failed check means the signed content no longer matches the signature, indicating modification in transit or after signing.

Why this answer

A failed DKIM check indicates that the email's content has been modified since it was signed by the sending domain's private key. DKIM uses an asymmetric cryptographic signature (typically RSA or ECDSA) to ensure the integrity of specific header fields and the body hash. When the signature verification fails, it means the hash computed from the received message does not match the decrypted hash from the signature, proving tampering or corruption.

Exam trap

EC-CHFI often tests the distinction between DKIM verification failure (integrity check) and domain alignment (DMARC), so candidates mistakenly choose the domain mismatch option when the question specifically asks about a failed DKIM check.

How to eliminate wrong answers

Option B is wrong because a proxy server does not inherently cause a DKIM failure; DKIM verifies the signature against the original signing domain's public key, and a proxy that does not alter the signed headers or body will not break the signature. Option C is wrong because DKIM support is a server-side (MTA) function, not a client-side feature; the email client does not perform DKIM signing or verification. Option D is wrong because a failed DKIM check does not indicate a domain mismatch; the DKIM-Signature includes the 'd=' tag specifying the signing domain, and a mismatch between the 'From' domain and the 'd=' domain would be a separate policy issue (e.g., DMARC alignment), not a cryptographic verification failure.

79
Multi-Selectmedium

Which TWO of the following are common indicators of a path traversal attack found in web server logs? (Select 2)

Select 2 answers
A.Requests containing a large number of User-Agent strings
B.Requests containing '../' sequences
C.Requests containing '<script>' tags
D.Requests containing '%2e%2e%2f'
E.Requests containing 'OR 1=1'
AnswersB, D

The literal '../' sequence is the most direct directory traversal pattern, made of two dots and a slash used to move up one directory level in a hierarchical file system. An attacker appends multiple instances (e.g., ../../../../etc/passwd) to escape the web root and read arbitrary files. Its presence in URI path or parameter values is a primary signature for path traversal detection.

Why this answer

Option B is correct because '../' is the canonical directory traversal sequence used to climb out of the web root and reference files outside the intended directory, so its appearance in request paths is a classic path traversal indicator. Option D is correct because '%2e%2e%2f' is the URL-encoded form of '../' (where %2e is '.', and %2f is '/'), and attackers frequently encode traversal sequences to bypass naive filters, making it an equally common log indicator. Option A is not a path traversal indicator; multiple or unusual User-Agent strings relate to client identification, bot activity, or user-agent spoofing, not directory traversal.

Option C describes '<script>' tags, which indicate cross-site scripting (XSS) attempts rather than path traversal. Option E describes 'OR 1=1', a SQL injection tautology used to bypass authentication or manipulate queries, not a file-path traversal technique.

Exam trap

EC-Council often tests that candidates recognize both raw and URL-encoded forms of path traversal sequences, as many mistakenly think only the raw '../' is an indicator, overlooking the encoded variant '%2e%2e%2f'.

80
MCQhard

During a cloud forensics investigation, an analyst examines AWS CloudTrail logs and finds an event with "userIdentity":{"type":"AssumedRole","arn":"arn:aws:sts::123456789012:assumed-role/AdminRole/i-0abcd1234efgh5678"}. What does the 'i-0abcd1234efgh5678' portion most likely represent?

A.The AWS account ID of the role's trusted entity
B.The role's unique identifier assigned by IAM
C.The unique ID of the IAM user who assumed the role
D.The session name, which is typically the EC2 instance ID
AnswerD

The session name is the correct field because, when an EC2 instance obtains temporary credentials through an instance profile, CloudTrail records that session name as the EC2 instance ID. It appears after the colon in the principalId, for example AROAI... : i-1234567890abcdef0, and as the final segment of the assumed-role ARN. Correlating this suffix with EC2 instance IDs enables the analyst to identify the exact instance that made the API call. This is why the session name, and not the role ID or account ID, is the key forensic attribute in this scenario.

Why this answer

In CloudTrail, when an EC2 instance assumes a role, the session name is often the instance ID. The 'i-' prefix and alphanumeric string indicate an EC2 instance ID.

81
MCQmedium

An incident responder is analyzing AWS CloudTrail logs to determine if an unauthorized user accessed an S3 bucket. Which of the following CloudTrail event fields should be examined to identify the IAM user or role that made the API call?

A.sourceIPAddress
B.eventSource
C.requestParameters
D.userIdentity
AnswerD

`userIdentity` is the correct field because CloudTrail populates it with the identity of the principal that made the request. It includes the type (IAMUser, AssumedRole, Root, etc.), the ARN, the account ID, the access key ID, and—for temporary credentials—the session context. This is the definitive attribute for mapping an event to a specific IAM user or role and is essential for attribution during incident response.

Why this answer

The userIdentity field contains details about the identity that made the request, including ARN, user name, and type (IAM user, role, etc.).

82
MCQeasy

In email forensics, which artifact is stored in Outlook's Personal Folders (.pst) files and can be analyzed using tools like Aid4Mail or EmailTracker?

A.Only the email body text
B.Emails and attachments only
C.Email headers only
D.Emails, attachments, calendars, contacts, and other mailbox items
AnswerD

A .pst is a comprehensive personal folders backup that stores an entire mailbox tree: email items with attachments, calendar entries, contacts, tasks, notes, and journal records, all as structured MAPI objects. This breadth is what makes it invaluable in investigations, as deleted or orphaned items may remain in free-space blocks or the folder hierarchy. Therefore the correct characterization is a full mailbox archive, not a subset.

Why this answer

Outlook Personal Folders (.pst) files are not limited to storing just email content; they are a comprehensive container for multiple mailbox items. In addition to emails and attachments, .pst files store calendars, contacts, tasks, notes, journal entries, and other mailbox artifacts. Tools like Aid4Mail and EmailTracker can parse the entire .pst structure to extract and analyze all these item types, making option D correct.

Exam trap

The CHFI exam often tests the misconception that .pst files only store emails and attachments, when in fact they are a full mailbox container that includes calendars, contacts, tasks, and other items.

How to eliminate wrong answers

Option A is wrong because .pst files store far more than just the email body text; they include headers, attachments, and other mailbox items. Option B is wrong because .pst files contain not only emails and attachments but also calendars, contacts, tasks, and other items. Option C is wrong because .pst files store the complete email object (body, headers, attachments) and other mailbox items, not just headers.

83
Multi-Selecteasy

A forensic analyst is examining a Docker container image for malware. Which TWO techniques can help analyze the image layers?

Select 2 answers
A.Use 'docker history' to view the build history of the image
B.Use 'docker images' to list all images
C.Use 'docker inspect' to view the image metadata
D.Use 'docker save' to export the image as a tar file and extract layers
E.Use 'docker export' on a running container
AnswersA, D

The docker history command lists each layer's creation instruction, size and originating command from the image manifest. This reveals suspicious build steps such as downloads or shell commands, satisfying the need to inspect layer provenance without running the container.

Why this answer

Option A is correct because 'docker history' displays the image's build history, showing each layer's creation command (from the Dockerfile instructions), sizes, and IDs, which lets a forensic analyst trace what was executed or added during the build and spot suspicious layers. Option D is correct because 'docker save' exports the full image (all layers plus metadata) as a tar archive, which can be extracted to inspect each layer's filesystem contents directly, including deleted or hidden files, without running the container. Option B is not suitable because 'docker images' only lists image names, tags, sizes, and IDs on the host; it provides no layer-level detail.

Option C is not the best fit because 'docker inspect' returns image metadata (config, environment, entrypoint, layer digests) but not the actual layer contents or build commands needed for deep layer analysis. Option E is incorrect because 'docker export' flattens a running container's filesystem into a single tar, losing the layer history and structure, and it targets containers rather than images.

Exam trap

EC-Council often tests the distinction between image-level commands (docker history, docker save) and container-level commands (docker export), trapping candidates who confuse exporting a container's filesystem with extracting image layers.

84
MCQeasy

Which tool is specifically designed to extract and analyze email metadata, including headers, from various email client formats such as PST and OST files?

A.Wireshark
B.EmailTracker
C.Aid4Mail
D.FTK Imager
AnswerC

Aid4Mail is a dedicated forensic email extraction and conversion tool engineered to parse Outlook PST/OST, MBOX, EML, MSG, and numerous other formats while preserving header fields, routing data, attachments, and internal metadata. It creates court-defensible exports with hash integrity and can process large mail stores with selective filtering, making it the appropriate tool for metadata and content analysis. This specialized parsing capability is exactly what distinguishes it from general-purpose forensic utilities.

Why this answer

Aid4Mail is a commercial forensic tool that can extract emails and metadata from PST, OST, MBOX, and other formats. EmailTracker is primarily for tracking email delivery, not forensic analysis of client files.

85
MCQmedium

An analyst reviews an Apache access log entry: '192.168.1.10 - - [10/Oct/2023:13:55:36 +0000] "GET /index.php?id=1%27%20OR%20%271%27%3D%271 HTTP/1.1" 200 1234 "-" "Mozilla/5.0"'. Which attack does this log entry most likely indicate?

A.SQL injection (SQLi) attack
B.Cross-site scripting (XSS) attack
C.Path traversal attack
D.Remote file inclusion (RFI) attack
AnswerA

The log entry contains classic SQL injection signatures: quote characters, SQL logical operators such as OR and AND, and observable query fragments like UNION SELECT. These tokens indicate an attempt to terminate a string literal and append a new SQL predicate to manipulate the database's response. A successful injection of this nature could allow an attacker to bypass authentication, extract data, or modify records, making this the correct classification.

Why this answer

The URL-encoded payload contains SQL injection syntax (%27 is a single quote), attempting to inject an OR condition. This is indicative of a SQL injection attempt.

86
MCQmedium

In an AWS environment, a security analyst detects unusual API calls that created several IAM users with administrative privileges from an unfamiliar IP address. Which AWS service log should be examined first to identify the specific API calls and the IAM user that made them?

A.Amazon S3 access logs
B.AWS CloudWatch Logs
C.AWS CloudTrail
D.AWS Config
AnswerC

CloudTrail records every AWS API call with the calling identity, source IP and timestamp, so the CreateUser and AttachUserPolicy events reveal both the IAM user and the unfamiliar address. This directly satisfies the stem's need to identify the specific API calls and their originator.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including the identity of the caller (IAM user or role), the source IP address, and the specific API actions (e.g., CreateUser, AttachUserPolicy). In this scenario, CloudTrail logs will directly show which IAM user made the unusual API calls from the unfamiliar IP address, enabling the analyst to trace the unauthorized activity.

Exam trap

EC-CHFI often tests the distinction between CloudTrail (API activity logging) and CloudWatch Logs (monitoring and log aggregation), leading candidates to mistakenly choose CloudWatch Logs because they think 'logs' implies all logging, but CloudTrail is the specific service for API call auditing.

How to eliminate wrong answers

Option A is wrong because Amazon S3 access logs record requests made to S3 buckets (e.g., GET, PUT, DELETE objects), not IAM management API calls like creating users or assigning policies. Option B is wrong because AWS CloudWatch Logs is a service for monitoring, storing, and accessing log files from various sources (e.g., application logs, system logs), but it does not natively capture AWS API calls; it can only ingest CloudTrail logs if configured, but it is not the primary source for API call records. Option D is wrong because AWS Config is a service for evaluating and auditing resource configurations and compliance over time, not for recording real-time API calls or identifying the specific user who made them.

87
MCQmedium

A forensic investigator is analyzing a cloud environment hosted on Amazon Web Services (AWS). A compromised EC2 instance was used to exfiltrate data to an external IP address. The investigator needs to determine which AWS API calls were made to modify security groups to allow outbound traffic to that IP. Which AWS service should the investigator use to obtain this information?

A.VPC Flow Logs
B.AWS Config
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail records API activity in an AWS account, including calls to modify security groups (e.g., AuthorizeSecurityGroupEgress). By analyzing CloudTrail logs, the investigator can identify who made the API call, when, and from which IP address, and the parameters including the allowed IP. This directly answers the question.

Why this answer

AWS CloudTrail is the service that logs all API activity in an AWS account, including security group modifications. It captures the identity of the caller, the time, the source IP, and the request parameters. CloudWatch Logs, AWS Config, and VPC Flow Logs do not provide this level of API call detail.

Therefore, CloudTrail is the correct source.

Exam trap

The trap here is assuming that VPC Flow Logs or AWS Config capture API call details, when they only show network traffic or resource configurations.

88
Multi-Selectmedium

A forensic analyst is examining MySQL binary logs to identify a data exfiltration event. Which TWO fields are most critical for reconstructing the stolen data?

Select 2 answers
A.Error code
B.Timestamp
C.Server ID
D.SQL statement
E.Thread ID
AnswersB, E

Binlog event headers include a timestamp (in seconds since epoch) that enables forensic reconstruction of the exact order in which transactions occurred. This chronology is essential for correlating binlog events with other logs (e.g., access logs) to pinpoint when data was accessed and exfiltrated, and for establishing a timeline of an attacker's actions.

Why this answer

Timestamp (B) is critical for reconstructing the stolen data because it establishes the exact sequence of events, allowing correlation with other logs (e.g., general query log) to pinpoint when exfiltration occurred. Thread ID (E) uniquely identifies the database connection; by correlating thread IDs across binary logs and general query logs, the analyst can trace all queries (including SELECTs) executed by the same connection, revealing the exfiltration queries that are not recorded in binary logs. Together, these fields enable chronological and connection-based reconstruction, compensating for the binary log's lack of SELECT logging.

Exam trap

EC-Council often tests the misconception that SQL statements are always present in binary logs. However, binary logs only record data-changing operations (INSERT, UPDATE, DELETE, DDL), not SELECT queries used for typical data exfiltration. The critical fields for reconstructing stolen data from binary logs are timestamp and thread ID, which allow correlation with other logs that capture the actual SELECT statements.

89
MCQeasy

A security analyst reviews an Apache access log entry: 192.168.1.5 - - [10/Jan/2024:08:12:35 +0000] "GET /index.php?id=1 UNION SELECT username,password FROM users-- HTTP/1.1" 200 4321 "-" "Mozilla/5.0". What type of attack is MOST likely indicated?

A.Cross-site scripting (XSS)
B.Path traversal
C.Remote file inclusion
D.SQL injection
AnswerD

The presence of UNION SELECT in the request parameter is a hallmark of in-band SQL injection. By injecting a quote to close the original SQL string and then using UNION, the attacker can append arbitrary columns to the result set and exfiltrate data from other tables. The server-side SQL query executes the combined statement, and the output is reflected in the HTTP response, allowing non-blind data extraction. This is why the log entry is correctly classified as SQL injection.

Why this answer

The log entry shows a UNION SELECT statement appended to the id parameter, which is a classic SQL injection attempt.

90
MCQhard

While investigating a compromised web server, you discover a file named 'shell.php' in the web root. The file contains the following code: <?php system($_GET['cmd']); ?>. Which of the following best describes this file?

A.A SQL injection script
B.A file upload vulnerability exploit
C.A backdoor trojan
D.A web shell
AnswerD

The artifact is a web shell: a server-side script (often PHP, ASPX, or JSP) that takes command strings from HTTP request parameters and executes them through functions such as system(), exec(), or Process.Start, then returns the output in the HTTP response. This gives the attacker a persistent, remote command-line interface on the web server whenever the script is accessible. Web shells are commonly uploaded via file upload vulnerabilities, then used for further compromise, credential harvesting, or pivoting inside the network.

Why this answer

The file 'shell.php' contains code that uses the PHP system() function to execute arbitrary operating system commands passed via the 'cmd' GET parameter. This is the classic definition of a web shell, which provides remote command execution on the server. It is not a SQL injection script, a file upload exploit, or a trojan in the traditional sense, as it directly accepts and runs system commands through HTTP requests.

Exam trap

EC-Council often tests the distinction between the tool used to gain access (e.g., a file upload exploit) and the payload left behind (e.g., a web shell), causing candidates to confuse the exploit method with the resulting backdoor artifact.

How to eliminate wrong answers

Option A is wrong because a SQL injection script exploits vulnerabilities in database queries, not system command execution via HTTP parameters. Option B is wrong because a file upload vulnerability exploit is a technique used to upload malicious files, not the malicious file itself. Option C is wrong because a backdoor trojan is typically a standalone executable that provides unauthorized remote access, whereas this is a server-side script that executes commands via HTTP GET requests.

91
MCQeasy

Which of the following is a primary challenge in cloud forensics due to the shared responsibility model?

A.Inability to perform live acquisition of volatile data without cooperation from the cloud provider
B.Data is always stored in a single jurisdiction
C.Lack of encryption support
D.Cloud logs are immutable and cannot be altered
AnswerA

In IaaS and PaaS cloud models, forensic investigators lack direct physical or administrative access to the hypervisor, host OS, or physical memory. Capturing volatile data such as RAM, kernel structures, and active network connections must therefore occur through the cloud provider's APIs, which often require explicit cooperation, credential delegation, or legal process. When the VM is stopped or terminated, that volatile evidence is irrevocably lost, making the inability to perform live acquisition without provider assistance a primary challenge and a critical violation of the order of volatility.

Why this answer

The shared responsibility model means the cloud provider controls the infrastructure, limiting the investigator's ability to acquire volatile data without provider support.

92
Multi-Selecthard

During a forensic analysis of a compromised web server, an investigator identifies the following log entries. Which THREE entries are the strongest indicators of a successful web shell upload? (Choose three.)

Select 3 answers
A.POST /upload.php HTTP/1.1 200 0
B.POST /uploads/shell.aspx HTTP/1.1 200 - -
C.GET /uploads/shell.aspx?cmd=dir HTTP/1.1 200 - -
D.GET /../../windows/system32/cmd.exe HTTP/1.1 404 - -
E.GET /images/logo.png HTTP/1.1 304 - -
AnswersA, B, C

A POST request to /upload.php that returns HTTP 200 with a zero-byte response body indicates the server accepted a client upload even though the reply was empty. In Apache access logs, the trailing '0' is the response size in bytes, so this record is consistent with a PHP upload handler completing successfully and not returning content. Combined with the known purpose of upload.php, this is a strong forensic foothold for a web shell planted through the application's file-upload feature.

Why this answer

Successful uploads of aspx or php files that contain web shell code (e.g., with cmd parameter) and subsequent access to those files are strong indicators. The 404 for cmd.exe indicates a path traversal attempt, not a web shell.

93
Multi-Selecthard

Which THREE of the following are challenges specific to container forensics? (Select THREE.)

Select 3 answers
A.Containers share the same kernel as the host, limiting isolation for forensic acquisition
B.Network isolation prevents packet capture
C.Ephemeral nature of containers leads to volatile evidence
D.Standard forensic imaging tools can be directly applied
E.Need to analyze layered image filesystem instead of a single disk image
AnswersA, C, E

Because containers execute as isolated processes on the host kernel rather than as separate operating systems, forensic acquisition of a container is effectively a host-level live response. Capturing process memory requires interacting with the host's /proc, which can alter state for the container, and kernel memory artifacts are shared across all containers, undermining a clean acquisition boundary. This limited isolation also means your imaging commands may be visible to or affect the target container, necessitating careful coordination.

Why this answer

Containers are ephemeral (volatile evidence), they share the host kernel (limited isolation), and they rely on layered images that must be analyzed. Standard disk imaging tools may not work; network isolation is not a specific challenge.

94
Multi-Selectmedium

A forensic analyst is examining a Google Cloud Platform (GCP) environment after a security incident. Which TWO GCP services should the analyst use to audit API activity and resource changes? (Select TWO.)

Select 2 answers
A.Cloud Asset Inventory
B.Cloud Audit Logs
C.Cloud Storage Object Change Notification
D.Cloud Monitoring
E.Cloud Functions
AnswersA, B

Cloud Asset Inventory is the correct answer because it maintains a comprehensive, historical record of resource metadata and configuration across Google Cloud. It periodically captures and snapshots the state of resources such as compute instances, IAM policies, and storage buckets, allowing forensic analysts to query for previous configurations and detect unintended changes. This service supports exports to BigQuery for long-term retention and analysis, making it the ideal tool for reconstructing resource drift or unauthorized modifications.

Why this answer

Cloud Audit Logs record API calls and resource changes, while Cloud Asset Inventory tracks resource history and configuration changes.

95
MCQhard

A forensic analyst is investigating a compromised Microsoft Exchange Server 2019. The attacker gained access to a mailbox and exfiltrated emails. The analyst needs to determine the exact time and IP address from which the attacker accessed the mailbox via Outlook Web App (OWA). Which Exchange log should the analyst examine to find this information?

A.Message tracking logs
B.IIS logs on the Exchange server
C.Exchange audit logs
D.Windows Security event logs
AnswerB

OWA is hosted in IIS, and IIS logs record HTTP requests to OWA virtual directories, including the client IP address, timestamp, username, and requested URL. By analyzing IIS logs, the analyst can identify successful logins and mailbox access, including the source IP and time. This makes IIS logs the correct source for this scenario.

Why this answer

IIS logs on the Exchange server capture HTTP requests to OWA, including the client IP address, timestamp, and username. This directly provides the time and IP address of the attacker's mailbox access. Other logs either lack IP address information or do not focus on OWA access.

Therefore, IIS logs are the correct source.

Exam trap

The trap here is confusing mailbox audit logs with IIS logs; audit logs show actions but not the client IP address.

96
Multi-Selecthard

A cloud forensic investigator is analyzing a GCP audit log entry for a Compute Engine instance. Which THREE fields are essential for identifying the user and operation performed?

Select 3 answers
A.requestMetadata.callerIp
B.methodName
C.resourceName
D.requestMetadata.userAgent
E.authenticationInfo.principalEmail
AnswersB, C, E

methodName is the fully qualified name of the API method invoked, such as v1.compute.instances.delete. This field is essential because it directly answers the investigator's primary question of what operation was performed on the resource. In Cloud Audit Logs, the methodName is what allows filtering for specific actions (e.g., deleting instances, modifying IAM policies) and is indispensable for reconstructing the sequence of events during an incident.

Why this answer

GCP audit logs include the principal email (authenticationInfo), operation type (methodName), and resource name (resourceName). IP address and user agent may be in requestMetadata but not always in every log entry.

97
Multi-Selectmedium

Which TWO of the following are common challenges specific to cloud forensics? (Select TWO)

Select 2 answers
A.Volatile memory acquisition
B.Inability to image hard drives
C.Data jurisdiction and legal compliance
D.Multi-tenancy and separation of data
E.Lack of proper tools
AnswersC, D

Data jurisdiction and legal compliance are central cloud-specific challenges because cloud providers distribute data across data centers in multiple countries, and each jurisdiction has its own data protection laws, cross-border data transfer rules, and government-access rights. Investigators may need to obtain evidence from a server in another nation, requiring mutual legal assistance treaties (MLATs) or statutory mechanisms like the U.S. CLOUD Act, and this can conflict with privacy regulations such as GDPR. These legal constraints affect what data can be legally accessed, preserved, and admitted as evidence, making jurisdiction a uniquely difficult issue for cloud investigations.

Why this answer

Option C (Data jurisdiction and legal compliance) is correct because cloud data is often stored across multiple geographic regions and controlled by different providers, so forensic investigators must navigate varying laws, privacy regulations (e.g., GDPR), and cross-border data-access rules that complicate evidence collection and chain of custody. Option D (Multi-tenancy and separation of data) is correct because cloud resources are shared among multiple customers on the same physical infrastructure, making it difficult to isolate one tenant's data and artifacts without affecting or exposing others, which is a challenge unique to cloud environments. Options A and B are not specific to cloud forensics: volatile memory acquisition is a general digital-forensics challenge present on any live system, and the inability to image hard drives is generally false since providers and customers can often snapshot or image volumes (though access may be restricted).

Option E is also not cloud-specific, as lack of proper tools is a generic limitation across many forensic domains rather than a challenge unique to cloud forensics.

Exam trap

EC-Council often tests the distinction between general forensic challenges and those unique to cloud environments, so candidates mistakenly select volatile memory acquisition (A) or lack of proper tools (E) because they are common in on-premises forensics, but they are not specific to the cloud's shared responsibility and multi-tenant model.

98
MCQeasy

Which of the following tools is specifically designed to analyze email headers and track the path of an email, providing information about delays and potential spoofing?

A.EmailTracker
B.Wireshark
C.FTK Imager
D.Autopsy
AnswerA

EmailTracker is purpose-built for email header analysis, with automated parsing of Received, Message-ID, and Authentication-Results fields to trace routing paths and detect spoofing. It decodes the raw header chain into a visual map of mail transfer, making it the only listed option that directly analyzes email headers as its primary function.

Why this answer

EmailTracker is a tool that analyzes email headers, visualizes the path, and helps identify spoofing and delivery delays.

99
MCQmedium

During a database forensic investigation, you need to review Microsoft SQL Server transaction logs to identify unauthorized data modifications. Which of the following SQL Server functions or commands is used to read the transaction log?

A.SELECT * FROM sys.dm_tran_database_transactions
B.DBCC LOG
C.fn_dblog
D.BACKUP LOG
AnswerC

fn_dblog is a table-valued function that accepts a starting and ending LSN and returns every transaction log record in that range, with columns such as Current LSN, Operation, Context, Transaction ID, Description, AllocUnitName, Page ID, and decoded row data. It allows an investigator to filter by operation type, transaction ID, or database object to reconstruct insert/update/delete activity, page allocations, and schema changes directly from the log. This makes it the standard, structured method for reviewing the actual log records during a database forensic investigation.

Why this answer

The fn_dblog function is the correct choice because it is the undocumented but widely used SQL Server function that reads the transaction log (LDF file) directly, allowing forensic examiners to view every logged operation including data modifications, schema changes, and transaction details. Unlike other DMVs or commands, fn_dblog provides a row-by-row dump of the log records, making it essential for identifying unauthorized changes at the transaction level.

Exam trap

EC-Council often tests the distinction between deprecated commands (DBCC LOG) and their modern replacements (fn_dblog), leading candidates to choose the familiar but outdated option B instead of the correct function C.

How to eliminate wrong answers

Option A is wrong because sys.dm_tran_database_transactions is a dynamic management view that shows metadata about currently active transactions (e.g., transaction ID, state, log space usage), but it does not read the actual transaction log records or provide historical log content. Option B is wrong because DBCC LOG is an undocumented command that was used in older SQL Server versions (prior to 2005) to read the transaction log, but it has been deprecated and replaced by fn_dblog; in modern SQL Server, DBCC LOG is no longer available or functional. Option D is wrong because BACKUP LOG is a command used to back up the transaction log to a file for point-in-time recovery, not to read or inspect the log contents for forensic analysis.

100
MCQmedium

In cloud forensics, which AWS service logs API calls for governance, compliance, and operational auditing, and is the primary source for detecting unauthorized access?

A.AWS CloudTrail
B.AWS Config
C.Amazon CloudWatch
D.AWS GuardDuty
AnswerA

AWS CloudTrail is the correct service for logging API calls in cloud forensics. It captures every management-plane API request and response across AWS services, recording the user identity, source IP address, timestamp, and request parameters. This immutable audit trail enables investigators to reconstruct exactly what actions were taken and by whom, satisfying both auditing and security analysis requirements.

Why this answer

AWS CloudTrail is the correct answer because it is the dedicated AWS service that records all API calls made to the AWS environment, capturing details such as the identity of the caller, the time of the call, the source IP address, and the request parameters. This log data is essential for governance, compliance, and operational auditing, and it serves as the primary forensic source for detecting unauthorized access or suspicious activities by providing an immutable record of who did what and when.

Exam trap

EC-CHFI often tests the distinction between services that generate logs (CloudTrail) versus services that analyze or monitor logs (GuardDuty, CloudWatch), leading candidates to mistakenly choose GuardDuty because it is associated with threat detection, even though it does not directly log API calls.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it focuses on evaluating and recording configuration changes to AWS resources against desired policies, not on logging API calls; it is used for compliance auditing of resource configurations, not for capturing API-level activity. Option C (Amazon CloudWatch) is wrong because it is a monitoring service for metrics, logs, and alarms, primarily used for operational health and performance monitoring, not for recording API calls for governance or forensic auditing. Option D (AWS GuardDuty) is wrong because it is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify malicious activity, but it does not itself log API calls; it consumes logs from other sources to generate findings.

101
MCQeasy

Which cloud service log is most appropriate for tracking API calls and resource changes in an AWS environment?

A.AWS VPC Flow Logs
B.AWS Config
C.AWS CloudTrail
D.AWS CloudWatch Logs
AnswerC

CloudTrail records AWS API activity and resource changes across the account, capturing who did what, when and from where. This directly satisfies the need to track API calls and resource modifications, unlike flow logs or CloudWatch metrics.

Why this answer

AWS CloudTrail is the service that records API activity and resource changes.

102
MCQmedium

During an investigation of a suspected data exfiltration, a forensic analyst examines MySQL general query logs and finds a large number of SELECT queries retrieving customer records, followed by DELETE queries. Which of the following is the most likely conclusion?

A.An attacker exfiltrating data and then deleting the records to cover tracks
B.An attempted SQL injection attack
C.A misconfigured replication process
D.Normal database maintenance operations
AnswerA

An attacker executing a SELECT to retrieve sensitive rows and then a DELETE on those exact rows is a classic data-exfiltration pattern. The sequential query log shows the attacker reading the data (SELECT) and then destroying the evidence of that read by removing the rows (DELETE), often using a WHERE clause matching the same primary keys or filters. This deliberate read-then-purge sequence is highly anomalous compared to normal application behavior and indicates an attempt to both steal data and cover forensic traces.

Why this answer

The combination of bulk SELECT (exfiltration) followed by DELETE (cover tracks) is a classic pattern of data theft.

103
MCQmedium

A cloud forensics investigator is analyzing an incident in AWS. The suspect is alleged to have deleted an S3 bucket. Which AWS service log would contain the DeleteBucket API call details, including the source IP and user identity?

A.AWS CloudTrail
B.VPC Flow Logs
C.Amazon S3 access logs
D.AWS Config
AnswerA

AWS CloudTrail is the correct answer because it is the primary service for logging all API activity in AWS, including management events like DeleteBucket. It records the identity of the principal who made the call, the source IP, the timestamp, and the request parameters, providing a complete audit trail for investigating management-plane incidents. Without CloudTrail, you would lack the forensic evidence of who issued the destructive bucket deletion command.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including management-plane operations like DeleteBucket. Each CloudTrail event contains the source IP address, user identity (IAM user or role ARN), and the exact API action (DeleteBucket), making it the definitive log for investigating S3 bucket deletion incidents.

Exam trap

The CHFI exam often tests the distinction between management-plane logs (CloudTrail) and data-plane logs (S3 access logs), so candidates mistakenly choose S3 access logs thinking they capture bucket deletion, when in fact they only log object-level operations within the bucket.

How to eliminate wrong answers

Option B (VPC Flow Logs) is wrong because they capture network traffic metadata (IP addresses, ports, protocols) at the VPC level, not API-level actions like S3 bucket deletion. Option C (Amazon S3 access logs) is wrong because they record object-level access requests (GET, PUT, DELETE) within a bucket, not the management-plane DeleteBucket API call that removes the bucket itself. Option D (AWS Config) is wrong because it tracks resource configuration changes and compliance over time, but it does not log the source IP or user identity for API calls; it only records the resulting state change.

104
Multi-Selecthard

Which THREE of the following are challenges specific to container forensics?

Select 3 answers
A.Ephemeral nature of containers: containers are often short-lived and can be deleted quickly
B.Containers cannot be imaged using standard forensic tools
C.Container logs are always stored in a centralized location
D.Multiple layers in a container image require analysis of each layer for forensic artifacts
E.Containers share the host kernel, so kernel-level artifacts are not available
AnswersA, D, E

Containers are designed to be short-lived and disposable, often existing for seconds or minutes during automated builds, batch jobs, or scaled-out microservices. Unlike VMs that persist as files on disk, a container's writable layer is typically deleted when the container stops, so forensic acquisition must occur live or immediately after the incident before the container is removed by orchestrators or cleanup daemons. Even the container ID, PID, and filesystem may vanish, making time-sensitive triage critical.

Why this answer

Option A is correct because containers are frequently ephemeral—they can be stopped, deleted, or replaced in seconds—so volatile evidence such as running processes, memory, and writable layer data may disappear before acquisition, making timely capture critical. Option D is correct because a container image is built from stacked layers (e.g., in OCI/Docker format), and each layer may contain distinct artifacts, deleted files, or modifications, so investigators must analyze every layer rather than just the final filesystem view. Option E is correct because containers share the host's kernel via namespaces and cgroups rather than running their own kernel, so kernel-level artifacts (e.g., kernel modules, some syscalls, and host-level kernel logs) are not isolated within the container and must be examined on the host instead.

Option B is not correct because containers and their images can be imaged or exported using standard tools such as docker export, docker save, or dd on the underlying storage, so this is not an inherent limitation. Option C is not correct because container logs are not always centralized; by default they are stored locally on the host (e.g., under /var/lib/docker/containers or via the configured logging driver), and centralization only occurs if a logging driver or aggregation system is explicitly configured.

Exam trap

A common misconception in CHFI is that containers are completely un-imageable with standard tools, but in reality, `docker export` and `docker save` produce standard archives that can be ingested by forensic suites.

105
MCQeasy

A security analyst is reviewing Apache access logs and finds the entry: 192.168.1.100 - - [10/Mar/2025:08:12:34 +0000] "GET /search?q=test' OR '1'='1 HTTP/1.1" 200 532. Which attack does this log entry most likely indicate?

A.Cross-site scripting (XSS)
B.Remote file inclusion (RFI)
C.SQL injection (SQLi)
D.Path traversal
AnswerC

The presence of a lone single quote followed by OR '1'='1 is a classic SQL injection signature because it breaks out of the string literal and makes the WHERE clause always true, potentially returning every record or bypassing authentication. If the application concatenates this input directly into a SELECT or login query, the attacker controls query logic beyond the intended parameter. The exact syntax is meaningful only in the context of SQL parsing, making SQLi the correct classification.

Why this answer

The presence of ' OR '1'='1 in the query string is a classic SQL injection attempt, designed to bypass authentication or extract data.

106
MCQhard

A forensic analyst is investigating a Docker container that was used to launch a network attack. The container has been stopped but not removed. Which action should the analyst take FIRST to preserve volatile evidence?

A.Restart the container and use 'docker exec' to collect evidence
B.Use 'docker inspect' to view container metadata only
C.Use 'docker save' to export the container as a tar file
D.Use 'docker commit' to create an image of the container
AnswerD

'docker commit' captures the container's current writable layer into a new image, preserving the filesystem state at a defined moment without modifying the original container's content. By default, Docker pauses the container during the commit, giving a point-in-time consistent snapshot that can be exported with 'docker save' and analyzed in a sandbox. This method is the best option listed because it preserves the container's filesystem evidence in a non-destructive way, although it does not capture live memory or active network connections.

Why this answer

Preserving the container's file system and logs is key. 'docker commit' creates an image from the container's current state. 'docker export' exports the filesystem as a tar archive. 'docker logs' retrieves logs. 'docker inspect' shows metadata. The container is stopped, so 'docker exec' won't work without starting it, which alters state. 'docker save' saves images, not containers. The best first step is to create an image or export the filesystem.

107
MCQmedium

An organization uses Azure. A security analyst needs to investigate a suspicious login event. Which Azure log contains details about user sign-ins, including IP address, timestamp, and success/failure status?

A.Azure Monitor Metrics
B.Azure AD Sign-in logs
C.Azure Activity Logs
D.Azure Security Center alerts
AnswerB

Azure AD Sign-in logs are the canonical record of user authentication events in Azure Active Directory. Each entry contains the user principal name, IP address, client application, timestamp, location, conditional access policies applied, and the sign-in status (success, failure, or interrupted). These logs cover interactive and non-interactive sign-ins and are accessible via the Azure portal, Microsoft Graph API, or by streaming to a SIEM. They provide the granular evidence needed to trace exactly when, from where, and how an account was accessed.

Why this answer

Azure AD Sign-in logs (Option B) are the correct source because they specifically capture user authentication events, including the IP address of the client, the exact timestamp of the sign-in attempt, and the success or failure status (e.g., 'Success', 'Failure', 'Interrupted'). This log is part of Azure Active Directory's monitoring suite and is designed for identity-related forensic investigations, unlike infrastructure or resource-level logs.

Exam trap

The trap here is that candidates often confuse Azure Activity Logs (control-plane) with Azure AD Sign-in logs (identity-plane), mistakenly thinking that resource-level logs capture user authentication events.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Metrics stores numerical performance data (e.g., CPU usage, request counts) and does not contain user sign-in details like IP addresses or success/failure status. Option C is wrong because Azure Activity Logs record control-plane operations on Azure resources (e.g., creating a VM, modifying a network security group) and do not include user authentication events. Option D is wrong because Azure Security Center alerts provide security threat notifications (e.g., detected malware, suspicious network activity) but do not serve as a raw log of sign-in events with IP and timestamp details.

108
MCQeasy

Which cloud forensic challenge refers to the inability to physically access the storage media where data resides?

A.Data jurisdiction
B.Lack of physical access
C.Multi-tenancy
D.Volatility of evidence
AnswerB

Lack of physical access means investigators cannot directly seize or image the underlying magnetic media or solid-state drives that store cloud data, because those devices reside in provider-managed data centers. This forces reliance on logical acquisition through provider APIs or legal processes, making it difficult to verify the integrity and chain of custody of the evidence. It is the core forensic challenge that distinguishes cloud investigations from traditional on-premises computer forensics.

Why this answer

Cloud forensics often involves data stored on remote servers managed by a cloud service provider (CSP). Forensic investigators cannot physically seize or access the hard drives or SSDs due to the CSP's infrastructure and security policies, making physical access impossible. This lack of physical access is a fundamental challenge that distinguishes cloud forensics from traditional digital forensics, where the media can be physically acquired and imaged.

Exam trap

EC-Council CHFI exam often tests the distinction between 'lack of physical access' and 'multi-tenancy' by presenting multi-tenancy as a plausible answer, but the key is that multi-tenancy is about resource sharing, not the inability to physically touch the storage media.

How to eliminate wrong answers

Option A is wrong because data jurisdiction refers to legal and regulatory issues regarding where data is stored geographically, not the physical inability to access storage media. Option C is wrong because multi-tenancy describes the sharing of physical resources among multiple tenants, which introduces data separation and privacy concerns, but it does not directly address the inability to physically access the storage media. Option D is wrong because volatility of evidence concerns the ephemeral nature of data in memory or temporary storage that can be lost quickly, not the physical inaccessibility of persistent storage media.

109
MCQmedium

In cloud forensics, which AWS service provides a centralized log of API calls made by users and services, often used to investigate unauthorized access or configuration changes?

A.AWS CloudWatch
B.AWS CloudTrail
C.AWS Config
D.AWS VPC Flow Logs
AnswerB

CloudTrail is the correct AWS service because it continuously records API activity across your account, capturing each call's identity, source IP, timestamp, request parameters, and response elements. It delivers immutable event history to S3 for long-term retention and enables centralized, cross-region and cross-account trails, making it the primary evidence source for reconstructing attacker actions during forensic investigations.

Why this answer

AWS CloudTrail records all API calls for governance, compliance, and operational auditing, making it essential for forensic investigations in AWS.

110
MCQmedium

During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API call and the associated IAM user or role?

A.AWS CloudTrail
B.Amazon S3 server access logs
C.AWS Config
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail is the primary forensic source because it records management events in the S3 control plane, including the DeleteBucket API call that removes a bucket. Each event captures the calling user's IAM identity or federated principal, source IP address, event time, and request parameters, enabling attribution. CloudTrail is enabled by default for management events, preserving this evidence without pre-provisioning.

Why this answer

AWS CloudTrail records API calls made to AWS services, including S3 bucket deletion, along with the identity of the caller.

111
Multi-Selectmedium

Which TWO pieces of information can be obtained from an email's Received headers to help trace the email's origin? (Select TWO)

Select 2 answers
A.The DKIM signature hash
B.The sender's email client version
C.The IP address of the originating mail server
D.The subject line of the email
E.The timestamp when the email was processed by each server
AnswersC, E

The first Received header in an email contains the originating IP address of the server, or sometimes the actual client, that connected to the first hop MTA. For example, a trace line like 'Received: from [192.0.2.15] (unknown [192.0.2.15])' exposes the source IP as observed by the receiving server. This IP is fundamental to source attribution because it identifies the initial relay point in the message's path, even if the envelope sender is forged.

Why this answer

Option C is correct because Received headers record the connecting host's IP address (typically in the form 'Received: from mail.example.com ([192.0.2.1]) by ...'), which lets an investigator identify the originating mail server and trace the message's path back toward its source. Option E is correct because each Received header includes a date/time stamp showing when that hop processed the message, allowing analysts to reconstruct the chronological relay chain and spot delays or anomalies. The unmarked options do not belong: the DKIM signature hash (A) appears in the DKIM-Signature header, not Received; the sender's email client version (B) is not a standard Received field (it may appear in User-Agent or X-Mailer headers); and the subject line (D) is carried in the Subject header, which is unrelated to routing information.

Exam trap

The EC-CHFI exam often tests the misconception that the DKIM signature hash or subject line is part of the Received headers, when in fact Received headers only contain routing information (IPs, hostnames, timestamps) and not message content or cryptographic signatures.

112
MCQeasy

Which of the following email authentication protocols uses a digital signature to verify the sender's domain and that the email has not been tampered with?

A.DMARC
B.DKIM
C.SPF
D.STARTTLS
AnswerB

DKIM (DomainKeys Identified Mail) is the protocol that adds a digital signature to email headers, specifically a DKIM-Signature header containing a base64-encoded signature. The signing domain uses its private key to sign selected header fields and the message body, while the receiving MTA retrieves the public key via a TXT record in DNS (e.g., selector._domainkey.example.com) and verifies the signature. This cryptographically ties the message to the domain and ensures the signed content was not altered in transit.

Why this answer

DKIM (DomainKeys Identified Mail) is the correct answer because it uses a digital signature (an encrypted hash) added to the email header, which is verified against a public key published in the sender's DNS TXT record. This cryptographic process confirms that the email originated from the claimed domain and that the message body and key headers have not been altered in transit, ensuring integrity and authenticity.

Exam trap

A common trap in the EC-CHFI exam is that candidates confuse STARTTLS's transport-layer encryption with message-level authentication, leading them to pick D instead of the correct digital signature protocol.

How to eliminate wrong answers

Option A (DMARC) is wrong because DMARC is a policy framework that uses SPF and DKIM results to instruct receivers on how to handle unauthenticated mail (e.g., quarantine or reject); it does not itself create or verify digital signatures. Option C (SPF) is wrong because SPF only checks the envelope sender (Return-Path) against a list of authorized IP addresses in DNS; it provides no cryptographic integrity or tamper detection. Option D (STARTTLS) is wrong because STARTTLS is a protocol command (defined in RFC 3207) that upgrades an existing plaintext SMTP connection to an encrypted TLS session; it protects the channel but does not authenticate the sender's domain or verify message integrity after delivery.

113
MCQmedium

Which Azure log source should an investigator query to identify who deleted a virtual machine and when?

A.Azure Activity Log
B.Azure Active Directory sign-in logs
C.Azure Diagnostic Settings for the VM
D.Network Security Group flow logs
AnswerA

Azure Activity Log records control-plane operations on subscriptions, including the identity that issued a virtual machine deletion and its timestamp. It satisfies the requirement to attribute the deletion to a specific principal, unlike data-plane or guest OS logs, which capture runtime events rather than management actions.

Why this answer

The Azure Activity Log (formerly known as Audit Logs) is the subscription-level log that records all control-plane operations on Azure resources, including virtual machine creation, deletion, and modification. When a VM is deleted, the Activity Log captures the operation name (e.g., 'Microsoft.Compute/virtualMachines/delete'), the caller's identity (user or service principal), the timestamp, and the status of the operation. This makes it the authoritative source for answering 'who deleted a VM and when'.

Exam trap

Candidates often confuse authentication logs (such as sign-in logs) with resource operation logs (such as activity logs). Authentication logs only show login events, not the actions performed after login. To determine who deleted a VM, you need the activity log that records control-plane operations.

How to eliminate wrong answers

Option B is wrong because Azure AD sign-in logs track authentication events (user logins, MFA challenges, token issuance) but do not record resource-level operations like VM deletion; they are identity-focused, not resource-focused. Option C is wrong because Azure Diagnostic Settings for a VM collect guest OS-level logs (e.g., event logs, performance counters, IIS logs) and are not aware of control-plane operations such as VM deletion, which occur at the Azure Resource Manager layer. Option D is wrong because Network Security Group flow logs capture IP traffic flows (source/destination IP, port, protocol) through NSGs and are used for network forensics, not for tracking who performed a resource management action like deleting a VM.

← PreviousPage 2 of 2 · 113 questions total

Ready to test yourself?

Try a timed practice session using only Application, Email and Cloud Forensics questions.