CHFI Application, Email and Cloud Forensics Practice Question
In Docker forensics, which of the following commands would you use to inspect the history of an image, including the commands that created each layer?
⚠ Common exam trap
EC-Council CHFI often tests the distinction between `docker inspect` (which shows metadata) and `docker history` (which shows layer creation commands), leading candidates to confuse the two when asked about build history.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
docker history
The `docker history` command displays the history of an image, showing each layer along with the command that created it. This is essential in forensic investigations to trace how an image was built, including any potentially malicious commands embedded in the layers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
docker image ls
Why it's wrong here
The `docker image ls` command enumerates all locally stored images, displaying their repository, tag, image ID, creation timestamp, and virtual size, but it only provides a flat inventory of image artifacts on the host. It does not expose the sequence of build steps, intermediate layers, or the specific Dockerfile instructions used to assemble an image. In forensics, this command helps identify which images are present, but it cannot reconstruct the provenance or layered construction of a particular image.
- ✓
docker history
Why this is correct
The `docker history` command displays the full layer chain of an image, listing each layer's ID, creation time, size, and the corresponding build command (e.g., RUN, COPY, ENV) that produced it. This makes it the definitive tool for forensically reconstructing how an image was built, as it reveals every instruction executed during the build process, including potentially malicious commands embedded in a Dockerfile. It also shows 'missing' intermediate layers that are not physically stored on the host, providing a complete timeline of image assembly.
- ✗
docker logs
Why it's wrong here
The `docker logs` command retrieves only the standard output and standard error streams emitted by a container during its runtime, capturing application-generated messages and error traces. It has no relation to the image build process and cannot expose how layers were created or what commands were used to build the image. In forensic investigations, `docker logs` is used to analyze container behavior and runtime events, not to understand the immutable structural history of an image.
- ✗
docker inspect
Why it's wrong here
The `docker inspect` command returns low-level JSON metadata for a container, image, volume, or network, including configuration details like environment variables, entrypoint, exposed ports, and mount points. For images, it reports information such as the architecture, OS, and default configuration, but it does not list the chronological sequence of build commands or layer composition. While older Docker versions exposed a 'Parent' field hinting at inheritance, modern storage drivers like overlay2 store layer metadata differently, making `docker history` the authoritative command for layer-level forensics.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.