CHFI Database and Application Forensics Practice Question
A forensic investigator is examining a compromised database server running Microsoft SQL Server 2019. The attacker gained access and executed several destructive queries. The investigator needs to determine the exact time and text of the malicious queries. The database is configured with the full recovery model, and transaction log backups are available. Which of the following should the investigator use to recover the query text?
⚠ Common exam trap
The trap here is assuming that built-in SQL Server functions like sys.fn_dblog provide complete query text without additional parsing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a third-party log reader tool that parses the transaction log and extracts the query text from log records, such as ApexSQL Log or Quest Toad.
The transaction log in full recovery model records all transactions, but the native sys.fn_dblog function does not directly provide query text. Specialized third-party log reader tools can interpret log records and reconstruct the original queries, including the exact text and timing. This is the most reliable method for forensic recovery of query text from SQL Server transaction logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore the database from the last full backup, then use SQL Server Profiler to capture live queries as they are re-executed.
Why it's wrong here
Restoring from backup and using SQL Server Profiler would capture new queries, but it does not recover the historical malicious queries that were already executed. Profiler captures current activity, not past events. This approach would not provide the original query text from the incident.
- ✓
Use a third-party log reader tool that parses the transaction log and extracts the query text from log records, such as ApexSQL Log or Quest Toad.
Why this is correct
Third-party log reader tools can parse the transaction log and reconstruct the exact query text from log records, including the time and user. They are designed for forensic analysis of SQL Server logs and can extract detailed information even from inactive log portions, provided the log has not been truncated.
- ✗
Use the sys.fn_dblog function to read the active transaction log and filter for LOP_INSERT_ROWS and LOP_DELETE_ROWS operations.
Why it's wrong here
The sys.fn_dblog function can read the active transaction log, but it does not directly provide the query text. It returns log records with operation types, but reconstructing the full query requires additional parsing and may not capture all details if the log has been truncated. This method is incomplete for recovering exact query text.
- ✗
Use the sys.dm_exec_query_stats dynamic management view to retrieve the query text and execution statistics.
Why it's wrong here
The sys.dm_exec_query_stats view provides aggregated performance statistics for cached query plans, not historical query text from the transaction log. It may show recent queries, but it does not retain the exact text or time of past malicious queries, especially after a server restart or plan eviction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.