CHFI Application, Email and Cloud Forensics Practice Question
Which TWO of the following are valid methods to collect logs from Docker containers for forensic analysis? (Select TWO)
⚠ Common exam trap
EC-Council often tests the distinction between commands that retrieve logs (`docker logs`, `docker cp`) versus commands that inspect configuration or modify the container, leading candidates to mistakenly select `docker inspect` or `docker exec` as log collection methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using docker logs command to retrieve container logs
Option A is correct because the `docker logs` command retrieves the stdout/stderr output captured by the container's configured logging driver (e.g., json-file, journald), which is the primary source of application logs for forensic review. Option C is correct because `docker cp` allows an investigator to copy log files written inside the container's filesystem (e.g., /var/log/app.log) to the host for offline analysis, which is essential when logs are not sent to stdout/stderr. Option B is not a collection method; `docker inspect` only reveals the logging driver and configuration (such as LogPath), not the log contents themselves. Option D is not a valid collection method because running syslog inside the container starts a new logging service rather than extracting existing container logs. Option E is incorrect because `docker image` inspects image layers and metadata, which contain no runtime container logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using docker logs command to retrieve container logs
Why this is correct
The `docker logs` command is the canonical method for retrieving the console output of a container, as it reads the stdout and stderr streams that were captured by the container runtime. By default, these streams are stored in a JSON-file log on the host under `/var/lib/docker/containers/<container-id>/<container-id>-json.log`, and `docker logs` presents them in a human-readable format. It also supports flags like `--since`, `--tail`, and `--follow` to filter or stream the logs, making it a direct and efficient way to collect a container's standard output without needing to access its filesystem.
- ✗
Using docker inspect to get log configuration
Why it's wrong here
`docker inspect` returns extensive metadata about a container, including its configuration, state, network settings, and the logging driver configuration (for example, the `LogConfig` object with driver type and options). However, this command only shows metadata describing how logging is configured—it does not extract or display the actual log entries contained in that log. To collect the raw logs, you must use `docker logs` to read the captured streams or `docker cp` to copy the underlying log files from the container or the host log directory.
- ✓
Copying log files from the container using docker cp
Why this is correct
`docker cp` is a valid collection method because it copies files or directories directly from the container's filesystem to the host, allowing you to retrieve log files that an application wrote to disk, such as `/var/log/nginx/access.log` or `/var/log/app.log`. This is particularly useful when the application logs to a file rather than to standard output, because `docker logs` would not capture those file-based logs. The syntax `docker cp <container>:/path/to/log /local/destination` works even if the container is stopped, as long as the container still exists, making it a reliable method for preserving logs during incident response.
- ✗
Using docker exec to run syslog inside the container
Why it's wrong here
Using `docker exec` to run `syslog` inside a container is not a reliable log collection method because most containers do not have a syslog daemon installed or running, and `docker exec` can only execute commands in a running container. Even if you manually start `syslog`, the logs written by the application prior to that point would not be retroactively captured, and the container's filesystem is often ephemeral. The recommended approach is to use `docker cp` to copy the existing log files from the container's filesystem, rather than trying to invoke a service that may not be present.
- ✗
Using docker image to view the image layers
Why it's wrong here
The `docker image` command (or `docker image ls`) is used to list and inspect container images, which are read-only templates composed of layers built from the Dockerfile. Logs are generated at runtime when a container is running and are stored in the container's writable layer or in a logging driver's external store—they are not part of the image itself. Therefore, examining image layers or metadata reveals nothing about the actual log entries, making this command irrelevant for log collection and a clear wrong answer.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.