Courseiva

CHFI Database and Application Forensics Practice Question

A forensic investigator is examining a MySQL database server that was compromised. The investigator needs to determine which user account was used to perform unauthorized modifications to a critical table. The MySQL server has the general query log enabled. Which of the following should the investigator review to find the user account associated with the modifications?

⚠ Common exam trap

The trap here is assuming that the binary log contains user information because it records data changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The MySQL general query log

The MySQL general query log captures all SQL statements along with the user account and connection information. This makes it the ideal source for determining which user executed specific modifications. Other logs like the error log, binary log, and slow query log do not provide the user account context needed for this forensic task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The MySQL slow query log

    Why it's wrong here

    The MySQL slow query log records queries that exceed a specified execution time threshold. It does not include the user account for each query, and it only captures a subset of queries. It is used for performance tuning, not for forensic auditing of user actions. Therefore, it is not suitable for identifying the user who made unauthorized modifications.

  • ✓

    The MySQL general query log

    Why this is correct

    The MySQL general query log records all SQL statements received from clients, along with the user account and connection details. By reviewing this log, the investigator can identify the exact queries that modified the table and the user account that executed them. This is the correct source for this information.

  • ✗

    The MySQL error log

    Why it's wrong here

    The MySQL error log records server startup and shutdown events, as well as errors and warnings. It does not contain information about individual SQL queries or the user accounts that executed them. Therefore, it cannot be used to identify the user who performed unauthorized modifications.

  • ✗

    The MySQL binary log

    Why it's wrong here

    The MySQL binary log records data modifications but does not include the user account that performed them. It is used for replication and point-in-time recovery, not for auditing user activity. While it can show what changes were made, it lacks the user context needed to identify the responsible account.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.