Be able to read a recovered database log entry and state exactly what it proves: which user acted, when, and what changed. The critical skill is knowing which log or audit feature records user attribution, and that full recovery model plus an intact log backup allows recovery of dropped objects.
Start practicing
Database and Application Forensics — choose a session length
Free · No account required
Domain overview
This domain covers forensic examination of database management systems and application artifacts: transaction logs, binary logs, audit trails, and recovery behavior. Questions present recovered log entries, exhibits, or incident scenarios involving MongoDB, MySQL, and Microsoft SQL Server, asking you to identify what a log record proves, which feature captured it, and what data survives a destructive operation.
Exam objectives
MongoDB logs and auditing features that attribute write operations to specific authenticated users
MySQL binary log event structure, including header timestamps and statement versus row-based entries
SQL Server full recovery model transaction log contents and point-in-time restore capability
Recovering dropped or deleted table data from SQL Server transaction log backups
Reading a MySQL binary log timestamp as the event's execution time rather than the server's log-write time in the configured timezone.
Assuming a DROP TABLE is unrecoverable under full recovery model when the log backup taken afterward still permits restoration.
Confusing MongoDB connection, slow-query, or replication logs with the audit log that actually records the acting user.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An organization uses Microsoft SQL Server 2019 with full recovery model. A database administrator accidentally executed a DROP TABLE statement. The transaction log was backed up immediately after the incident. Which forensic technique would allow the analyst to restore the dropped table?
2During a forensic investigation of a MongoDB database, the analyst needs to identify which user executed a particular write operation. Which MongoDB log or feature should the analyst examine?
3Refer to the exhibit. An analyst recovers this binary log entry from a MySQL server. What does the timestamp '190101 10:00:00' represent?
4You are a forensic investigator responding to an incident at a financial institution. The organization uses Microsoft SQL Server 2016 for its transaction processing system. The database is configured with full recovery model and transaction log backups are taken every 15 minutes. The incident response team has identified that an attacker gained access to the database server via compromised credentials and executed a series of malicious SQL statements, including data exfiltration and deletion of critical records. The time of the attack is estimated to be between 2:00 PM and 2:05 PM. The last full backup was taken at 12:00 AM (midnight) the same day. Transaction log backups are available for the entire day. The last transaction log backup before the attack was taken at 1:45 PM. The next transaction log backup after the attack was taken at 2:15 PM. The database is still online and being used by the business. Management wants to recover the database to a point just before the attack (2:00 PM) to minimize data loss, while preserving evidence for investigation. Which of the following actions should you take FIRST?
5During a database forensic investigation, an analyst recovers a MySQL binary log file (binlog.000012) from a compromised server. Which command should the analyst use to extract the actual SQL statements from this binary log in a human-readable format?
6Refer to the exhibit. A database administrator finds the above error log entries when attempting to start the MySQL service. The server was working fine yesterday. What is the most likely cause of this issue?
7A forensic investigator is analyzing a Microsoft SQL Server instance that was compromised. The investigator wants to identify all login attempts that failed due to incorrect passwords. Which system function or view should be queried?
8A forensic investigator is examining a compromised database server running Microsoft SQL Server 2019. The attacker gained access and executed several destructive queries. The investigator needs to determine the exact time and text of the malicious queries. The database is configured with the full recovery model, and transaction log backups are available. Which of the following should the investigator use to recover the query text?
9A forensic investigator is examining a MySQL database server that was compromised. The investigator needs to determine which user account was used to perform unauthorized modifications to a critical table. The MySQL server has the general query log enabled. Which of the following should the investigator review to find the user account associated with the modifications?
Be able to read a recovered database log entry and state exactly what it proves: which user acted, when, and what changed. The critical skill is knowing which log or audit feature records user attribution, and that full recovery model plus an intact log backup allows recovery of dropped objects.
The Courseiva CHFI question bank contains 9 questions in the Database and Application Forensics domain, covering the 7% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Database and Application Forensics domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included