CHFI OS and Network Forensics Practice Question
During a forensic analysis of a Linux system, the investigator finds that the bash_history file is empty for the root user. However, the system has been used actively. What is the MOST likely explanation?
⚠ Common exam trap
Investigators sometimes overlook the possibility that an empty bash_history file may be due to configuration variables like HISTSIZE or HISTFILE, rather than assuming user deletion or corruption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The HISTSIZE environment variable is set to 0 or the history file is redirected to /dev/null
The HISTSIZE environment variable controls how many commands are retained in memory during a session. When set to 0, no commands are stored, and the history file (typically ~/.bash_history) remains empty. Alternatively, if HISTFILE is redirected to /dev/null, all history writes are discarded, explaining the empty file despite active use.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system was shut down improperly
Why it's wrong here
An improper shutdown, such as a power failure or kernel panic, prevents bash from executing its EXIT trap, which normally flushes the in-memory history list to HISTFILE. As a result, the last session's commands would be lost, but previously saved history from earlier sessions would remain on disk. An empty .bash_history would therefore be unusual unless this was the very first session ever run, making this an unlikely primary explanation.
- ✗
The file is corrupted
Why it's wrong here
File corruption from a filesystem or storage fault would typically manifest as read errors, invalid characters, or partial records, not as a cleanly zero-length file. An empty file is a valid inode with size 0 and no allocated data blocks, which is not what one expects from corruption that damages content. Forensic tools would also detect checksum mismatches or journal inconsistencies rather than a simple empty file.
- ✗
The user deleted the history
Why it's wrong here
Deleting the history file after the fact with `rm` would remove the directory entry and inode entirely, leaving no file at all, whereas clearing the in-memory history with `history -c` only affects the current shell and does not immediately truncate HISTFILE until a later write. To leave an empty file, a user would have to explicitly run `> .bash_history` or `history -w` after clearing, which is a deliberate and relatively rare act compared to an environment misconfiguration. Thus, a pre-existing empty file is more consistent with history being disabled than with post-hoc deletion.
- ✓
The HISTSIZE environment variable is set to 0 or the history file is redirected to /dev/null
Why this is correct
When HISTSIZE is set to 0, bash immediately stops appending commands to the in-memory history list, and because the history file is only updated from that list on shell exit or explicit `history -w`, the result is an empty or nonexistent .bash_history. Similarly, configuring HISTFILE to point to /dev/null causes every write to go to a discard device, so no command history survives. Investigators should check the owning user's ~/.bashrc, ~/.bash_profile, and environment for these settings, as they are commonly used in privacy-conscious or automated environments.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.