CHFI Application, Email and Cloud Forensics Practice Question
During a forensic investigation of a compromised web server, you find the following entry in the IIS log: 192.168.2.50, -, 10/Jan/2023, 14:32:15, W3SVC1, WEB01, 192.168.2.10, 80, POST, /uploads/shell.aspx, 200, 0, 0, 513, 0, Mozilla/4.0. Which action should the investigator prioritize?
⚠ Common exam trap
EC-Council often tests the misconception that immediate remediation (deletion or rebuild) is the correct first step, but forensic methodology demands artifact preservation and analysis before any destructive action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze the uploaded shell.aspx file for malicious content
The IIS log entry shows a successful POST (HTTP 200) to /uploads/shell.aspx, which is a classic indicator of a web shell upload. The investigator's priority is to analyze the uploaded file to determine its capabilities, persistence mechanisms, and any data exfiltration or lateral movement it may have enabled. This aligns with forensic best practices: preserve and examine the artifact before taking remediation steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rebuild the web server from a clean backup
Why it's wrong here
Rebuilding the web server from a clean backup is a remediation step that, if performed before forensic imaging, destroys the original evidence needed to establish cause and scope. The backup may also reintroduce the same vulnerability if the root cause is not identified from the compromised system's artifacts. Proper incident response demands that investigation and evidence preservation precede any rebuild.
- ✓
Analyze the uploaded shell.aspx file for malicious content
Why this is correct
Analyzing the uploaded shell.aspx file is the most direct and probative step because it's an active web shell that confirms a successful exploitation and defines the attacker's capabilities. Static analysis (e.g., extracting strings, decoding obfuscated payloads) and dynamic analysis in a sandbox reveal command-and-control channels, file exfiltration methods, and any additional backdoors the shell installs. This knowledge is essential for both attribution and full remediation.
- ✗
Delete the shell.aspx file immediately
Why it's wrong here
Deleting the uploaded file immediately is dangerous from an evidentiary and investigative standpoint because it removes the artifact's hashes, timestamps, and file system metadata that are crucial to reconstructing the intrusion timeline. The file may also be tied to other artifacts—like scheduled tasks, registry entries, or memory-resident payloads—that would become irretrievable without coordinated capture. Forensic preservation must occur before any destructive action.
- ✗
Check the web server's firewall logs for the attacker's IP
Why it's wrong here
Firewall logs are useful for identifying the attacker's source IP, but they are network-layer evidence and often incomplete due to NAT, proxies, or log rotation, and they don't reveal the exploit technique or the shell's functionality. The uploaded file is a direct host-based indicator that confirms the attack vector and reveals intent, making it a higher priority than network logs. Also, firewall logs are typically stored remotely, so they can be preserved later without risking contamination of on-host evidence.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.