Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

During a forensic investigation of a compromised web server, you find the following entry in the IIS log: 192.168.2.50, -, 10/Jan/2023, 14:32:15, W3SVC1, WEB01, 192.168.2.10, 80, POST, /uploads/shell.aspx, 200, 0, 0, 513, 0, Mozilla/4.0. Which action should the investigator prioritize?

⚠ Common exam trap

EC-Council often tests the misconception that immediate remediation (deletion or rebuild) is the correct first step, but forensic methodology demands artifact preservation and analysis before any destructive action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyze the uploaded shell.aspx file for malicious content

The IIS log entry shows a successful POST (HTTP 200) to /uploads/shell.aspx, which is a classic indicator of a web shell upload. The investigator's priority is to analyze the uploaded file to determine its capabilities, persistence mechanisms, and any data exfiltration or lateral movement it may have enabled. This aligns with forensic best practices: preserve and examine the artifact before taking remediation steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rebuild the web server from a clean backup

    Why it's wrong here

    Rebuilding the web server from a clean backup is a remediation step that, if performed before forensic imaging, destroys the original evidence needed to establish cause and scope. The backup may also reintroduce the same vulnerability if the root cause is not identified from the compromised system's artifacts. Proper incident response demands that investigation and evidence preservation precede any rebuild.

  • ✓

    Analyze the uploaded shell.aspx file for malicious content

    Why this is correct

    Analyzing the uploaded shell.aspx file is the most direct and probative step because it's an active web shell that confirms a successful exploitation and defines the attacker's capabilities. Static analysis (e.g., extracting strings, decoding obfuscated payloads) and dynamic analysis in a sandbox reveal command-and-control channels, file exfiltration methods, and any additional backdoors the shell installs. This knowledge is essential for both attribution and full remediation.

  • ✗

    Delete the shell.aspx file immediately

    Why it's wrong here

    Deleting the uploaded file immediately is dangerous from an evidentiary and investigative standpoint because it removes the artifact's hashes, timestamps, and file system metadata that are crucial to reconstructing the intrusion timeline. The file may also be tied to other artifacts—like scheduled tasks, registry entries, or memory-resident payloads—that would become irretrievable without coordinated capture. Forensic preservation must occur before any destructive action.

  • ✗

    Check the web server's firewall logs for the attacker's IP

    Why it's wrong here

    Firewall logs are useful for identifying the attacker's source IP, but they are network-layer evidence and often incomplete due to NAT, proxies, or log rotation, and they don't reveal the exploit technique or the shell's functionality. The uploaded file is a direct host-based indicator that confirms the attack vector and reveals intent, making it a higher priority than network logs. Also, firewall logs are typically stored remotely, so they can be preserved later without risking contamination of on-host evidence.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.