Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

Which TWO of the following are indicators of a webshell attack found in web server logs? (Select TWO)

⚠ Common exam trap

EC-Council often tests the distinction between generic web anomalies (like high traffic or 404 errors) and webshell-specific indicators (like command parameters in script requests), so candidates mistakenly select broad traffic patterns instead of the precise log entries that reveal command execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Requests to a .asp or .php file with parameters like cmd or exec

Option C is correct because webshells are typically small scripts (e.g., .asp, .php, .jsp) that accept command parameters such as cmd, exec, or shell, so log entries showing requests to such files with those parameter names are a strong indicator of command execution through a webshell. Option E is correct because attackers commonly upload a webshell into a writable upload directory and then interact with it via POST requests, so repeated POSTs to a script in an upload folder in the web logs is a classic webshell traffic pattern. Option A is not specific to webshells, since OPTIONS and TRACE are legitimate HTTP methods and their presence alone does not indicate a webshell. Option B is too generic, as high traffic from one IP can result from many benign causes such as crawlers, load balancers, or DoS activity. Option D is also non-specific, because frequent 404 errors usually indicate broken links, scanning, or enumeration rather than webshell command execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Abnormal HTTP methods like OPTIONS or TRACE

    Why it's wrong here

    OPTIONS and TRACE are HTTP methods used for server capability discovery and diagnostics. While attackers may use them for reconnaissance or to exploit cross-site tracing vulnerabilities, they are not a reliable indicator of webshell activity because webshells typically rely on GET or POST requests that carry command parameters. The presence of OPTIONS or TRACE alone does not suggest a webshell is present.

  • ✗

    High volume of traffic from a single IP

    Why it's wrong here

    A high volume of traffic from a single IP address is a generic symptom of many attack patterns, including port scanning, denial-of-service, or credential stuffing. Webshell usage, in contrast, often produces only a small number of targeted requests from the attacker's IP, because the attacker is executing commands through the compromised page. Thus, while volume might warrant investigation, it is not a specific indicator of a webshell.

  • ✓

    Requests to a .asp or .php file with parameters like cmd or exec

    Why this is correct

    Webshells are often coded in dynamic script languages and expose command execution through parameters such as cmd, exec, or command. A request to a .asp or .php file that includes these parameter names strongly suggests an attacker is attempting to pass shell commands to the server. Such parameter names are unnatural for legitimate application workflows, making this a highly specific webshell indicator.

  • ✗

    Frequent 404 errors for non-existent pages

    Why it's wrong here

    Frequent 404 errors are typical results of directory brute-forcing, vulnerability scanning, or users following stale links, and they occur continuously across both benign and malicious traffic. A web shell, once uploaded, resides at a specific path and would generate successful responses (200) when invoked, not a stream of missing-page errors. Therefore, an abundance of 404s is not evidence of webshell compromise.

  • ✓

    POST requests to a script file in an upload directory

    Why this is correct

    Upload directories are typically meant to store static files like images or documents, not server-side scripts. When a POST request is directed at a script file located in such a directory, it indicates the script has been uploaded and the attacker is sending data to it, which is a common webshell interaction pattern. This behavior is highly suggestive of an active webshell because it shows the executable file was placed and is being used as intended.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.