Courseiva

CHFI · topic practice

Application, Email and Cloud Forensics practice questions

This domain covers forensic acquisition and analysis of application, email, and cloud evidence. Expect questions on email header fields that reveal true origin, cloud log sources like AWS CloudTrail and S3 access logs, jurisdictional and multi-tenancy challenges, and API-level attribution of user actions in cloud environments.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Application, Email and Cloud Forensics

What the exam tests

What to know about Application, Email and Cloud Forensics

A candidate must be able to select the right email headers for origin and the right cloud log for API attribution. The single most important thing is knowing that CloudTrail records API activity and the IAM principal, while email origin comes from Received and Return-Path.

Identifying originating IP and sender from Received and Return-Path headers

Using AWS CloudTrail to trace API calls and IAM identities

Recognizing multi-jurisdiction data storage as a legal challenge

Analyzing cloud service logs for resource deletion and configuration changes

Watch out for

Common Application, Email and Cloud Forensics exam traps

  • ▸Assuming the From header shows the true sender; it is easily spoofed and not reliable for origin.
  • ▸Confusing CloudTrail with S3 access logs or VPC Flow Logs when tracking API calls and IAM users.
  • ▸Overlooking that cloud data may reside in multiple legal jurisdictions, complicating subpoenas and preservation.

Practice set

Application, Email and Cloud Forensics questions

20 questions · select your answer, then reveal the explanation

During an investigation, an analyst extracts email headers from a suspicious email. The header includes: Received: from mail.attacker.com (192.168.1.100); DKIM-Signature: v=1; a=rsa-sha256; d=legitbank.com; s=selector1; bh=...; The email claims to be from support@legitbank.com. Which indicator strongly suggests email spoofing?

A forensic analyst is examining a Docker container suspected of being used for malicious activities. The container was running an Alpine Linux image and was stopped 2 hours ago. Which of the following is the BEST first step to collect volatile evidence?

Which tool is specifically designed to analyze email headers and track the path an email took across mail servers?

A forensic examiner needs to analyze a Microsoft Outlook PST file from a suspect's computer. Which tool is BEST suited to parse and extract emails, attachments, and metadata from the PST file?

Which of the following is a significant challenge in cloud forensics compared to traditional digital forensics?

During a forensic investigation of a suspected data breach, you are asked to analyze email headers to trace the origin of a phishing email. Which header field provides the IP address of the sending SMTP server?

An analyst finds the following entry in an IIS access log: 10.0.0.5, -, 10/10/2023, 14:30:22, W3SVC1, WEB01, 192.168.1.100, 80, GET, /login.aspx, 200, 0, 1234, 567, Mozilla/5.0+. Based on the log format, which field contains the HTTP status code?

Which THREE of the following are challenges specific to cloud forensics compared to traditional digital forensics? (Select 3)

In a database forensic investigation, you recover a MySQL binary log with the following entry: #230110 13:45:22 server id 1 end_log_pos 123456 Query thread_id=100 exec_time=0 error_code=0 SET TIMESTAMP=1673358322; SELECT * FROM customers INTO OUTFILE '/tmp/export.csv';. What does this indicate?

An email header shows the following Received line: Received: from mail.example.com (192.168.1.1) by smtp.server.com (Postfix). The DKIM-Signature header is missing, and the X-Originating-IP header shows an IP address different from the sender's domain MX record. What is the MOST likely conclusion?

During a cloud forensic investigation, you review AWS CloudTrail logs and find the following event: {"eventSource":"ec2.amazonaws.com","eventName":"RunInstances","userIdentity":{"arn":"arn:aws:iam::123456789012:user/attacker"},"requestParameters":{"instanceType":"t2.micro","imageId":"ami-0abcdef1234567890"},"responseElements":{"instancesSet":{"items":[{"instanceId":"i-0a1b2c3d4e5f67890"}]}}}. What is the immediate forensic action?

In Docker forensics, which command is used to view the command history of a container, including how it was built?

During a forensic investigation of a Microsoft SQL Server, you find the transaction log contains the following: LOP_BEGIN_XACT, LOP_INSERT_ROWS, LOP_COMMIT_XACT for a table named 'CreditCards', with a timestamp just before a known data breach. The log also shows a bulk insert operation. What does this indicate?

During a cloud forensic investigation, an analyst discovers that an AWS EC2 instance was used to launch an attack. The instance has been terminated. Which source is MOST likely to contain evidence of the commands executed on the instance?

An email investigator receives a suspicious email and examines the headers. The 'Received-SPF: pass (google.com: domain of example.com designates 203.0.113.5 as permitted sender)' header is present. However, the 'From' address is 'admin@example.com' and the 'Return-Path' is 'admin@example.com'. What does this indicate?

In a Docker container forensics investigation, an analyst needs to examine the file system of a stopped container to look for malicious artifacts. Which command should the analyst run to create a recoverable snapshot of the container's file system without starting the container?

A forensic analyst needs to extract email artifacts from a Microsoft Outlook .OST file that is associated with an Exchange account. Which tool is specifically designed to parse and analyze .OST files?

An investigator examines an email header and sees the following: 'DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=selector1; bh=...; h=...; b=...'. The email claims to be from 'support@example.com', but the DKIM signature validation fails. Which of the following is the MOST likely cause?

Which TWO of the following are valid indicators of email spoofing when analyzing email headers?

A forensic investigator examining a compromised Linux server finds a base64-encoded string in the Apache access log: 'GET /cgi-bin/test.cgi?cmd=ZWNobyAiPD9waHAgc3lzdGVtKCRfR0VUW2NtZF0pOyA/PiI+...' After decoding, the string contains a PHP webshell. Which of the following is the MOST effective method to confirm the webshell was executed on the server?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Application, Email and Cloud Forensics sessions

Start a Application, Email and Cloud Forensics only practice session

Every question in these sessions is drawn from the Application, Email and Cloud Forensics domain — nothing else.

Related practice questions

Related CHFI topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CHFI exam test about Application, Email and Cloud Forensics?
A candidate must be able to select the right email headers for origin and the right cloud log for API attribution. The single most important thing is knowing that CloudTrail records API activity and the IAM principal, while email origin comes from Received and Return-Path.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Application, Email and Cloud Forensics questions in a focused session?
Yes — the session launcher on this page draws every question from the Application, Email and Cloud Forensics domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CHFI topics?
Use the topic links above to move to related areas, or go back to the CHFI question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CHFI exam covers. They are not copied from any real exam or dump site.