Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

A forensic analyst is investigating a suspected data exfiltration from a MySQL database. Which log source would be MOST useful to identify the exact SQL queries executed, including SELECT statements that retrieved large volumes of data?

⚠ Common exam trap

The binary log only logs data-modifying statements (DML) and not read-only SELECTs, leading candidates to incorrectly choose Option B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MySQL general query log

The MySQL general query log records every SQL statement received from clients, including SELECT queries, making it the most useful source for identifying exact queries executed during a suspected data exfiltration. Unlike other logs, it captures all activity without filtering by error, execution time, or data-change events, so it will show the specific SELECT statements that retrieved large volumes of data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MySQL error log

    Why it's wrong here

    The MySQL error log is intended for server diagnostics, recording startup/shutdown events, critical errors, crash recovery information, and replication failures. It does not capture normal SQL statements, and certainly not SELECT queries executed by an application. A data exfiltration attempt that simply reads data via SELECT would not generate an error condition, leaving no trace in this log. Thus it is not an appropriate source for detecting query-based data theft.

  • ✗

    MySQL binary log

    Why it's wrong here

    The binary log (binlog) is purpose-built for replication and point-in-time recovery, so it only contains events that change data or schema—statements like INSERT, UPDATE, DELETE, and DDL. Because SELECT queries are read-only, they are never written to the binary log, regardless of how much sensitive data they retrieve. Therefore, while the binary log can show an attacker's modifications after exfiltration, it cannot reveal the SELECT statements used to steal data.

  • ✗

    MySQL slow query log

    Why it's wrong here

    The slow query log records only SQL statements whose execution time exceeds the configured long_query_time threshold (or that lack indexes), making it a performance-tuning tool rather than a complete audit trail. A malicious SELECT that extracts data from an indexed table in well under the threshold—often a few seconds or less—will never appear in this log. Thus, relying on it would miss any fast, optimized exfiltration queries.

  • ✓

    MySQL general query log

    Why this is correct

    The MySQL general query log captures every SQL statement received by the server—including SELECT, INSERT, UPDATE, and even malformed queries—along with connection events, regardless of how long each query takes. It provides a complete chronological record that an analyst can replay to spot suspicious patterns, such as repeated large-range SELECTs or queries targeting sensitive columns. With log_output set to TABLE, the log can be queried directly, making it the native MySQL mechanism for uncovering data exfiltration via SELECT.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.