Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

Which THREE of the following are challenges specific to container forensics? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Containers share the same kernel as the host, limiting isolation for forensic acquisition

Containers are ephemeral (volatile evidence), they share the host kernel (limited isolation), and they rely on layered images that must be analyzed. Standard disk imaging tools may not work; network isolation is not a specific challenge.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Containers share the same kernel as the host, limiting isolation for forensic acquisition

    Why this is correct

    Because containers execute as isolated processes on the host kernel rather than as separate operating systems, forensic acquisition of a container is effectively a host-level live response. Capturing process memory requires interacting with the host's /proc, which can alter state for the container, and kernel memory artifacts are shared across all containers, undermining a clean acquisition boundary. This limited isolation also means your imaging commands may be visible to or affect the target container, necessitating careful coordination.

  • ✗

    Network isolation prevents packet capture

    Why it's wrong here

    Network isolation via Linux network namespaces gives each container its own interface and routing table, but this does not block packet capture. You can simply run tcpdump inside the container's network namespace, or capture on the virtual ethernet (veth) pair on the host spanning to it. If capture is needed without entering the container, nsenter or switching into the namespace from a privileged host process achieves it.

  • ✓

    Ephemeral nature of containers leads to volatile evidence

    Why this is correct

    Containers are ephemeral and typically created for short-running tasks; a stopped container exits quickly and a deleted container removes its writable layer and runtime metadata. Live memory, open file descriptors, and uncommitted writes vanish with the container, leaving only the original read-only image. Consequently, waiting for a warrant or a slow ceremony can destroy the very evidence being sought, forcing first-responder triage.

  • ✗

    Standard forensic imaging tools can be directly applied

    Why it's wrong here

    Standard forensic imaging tools, such as dd, are designed to acquire contiguous block devices or entire physical disks, not the file-mounted directories and overlayfs layouts used by container runtimes. They cannot account for the copy-on-write nature of a container's writable layer, nor can they split an image into its constituent layers. A direct dd of the container's root might capture only a fuse/overlay view and miss deletion markers, requiring alternative tools like docker export.

  • ✓

    Need to analyze layered image filesystem instead of a single disk image

    Why this is correct

    A container image is a stack of read-only layers, each with its own changes, overlaid at runtime; forensic analysis requires flattening the layers, recognizing whiteout files for deleted entries, and matching layer IDs to image history. Tools like skopeo, crane, or docker history expose the layer chain, but a single bootable disk image does not exist. Only with this layered understanding can you reconstruct the exact state of the image and recover data hidden in lower layers.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.