CHFI Database and Application Forensics Practice Question
A forensic investigator is examining a MySQL database server that was compromised. The investigator needs to determine which user account was used to perform unauthorized modifications to a critical table. The MySQL server has the general query log enabled. Which of the following should the investigator review to find the user account associated with the modifications?
⚠ Common exam trap
The trap here is assuming that the binary log contains user information because it records data changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The MySQL general query log
The MySQL general query log captures all SQL statements along with the user account and connection information. This makes it the ideal source for determining which user executed specific modifications. Other logs like the error log, binary log, and slow query log do not provide the user account context needed for this forensic task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The MySQL slow query log
Why it's wrong here
The MySQL slow query log records queries that exceed a specified execution time threshold. It does not include the user account for each query, and it only captures a subset of queries. It is used for performance tuning, not for forensic auditing of user actions. Therefore, it is not suitable for identifying the user who made unauthorized modifications.
- ✓
The MySQL general query log
Why this is correct
The MySQL general query log records all SQL statements received from clients, along with the user account and connection details. By reviewing this log, the investigator can identify the exact queries that modified the table and the user account that executed them. This is the correct source for this information.
- ✗
The MySQL error log
Why it's wrong here
The MySQL error log records server startup and shutdown events, as well as errors and warnings. It does not contain information about individual SQL queries or the user accounts that executed them. Therefore, it cannot be used to identify the user who performed unauthorized modifications.
- ✗
The MySQL binary log
Why it's wrong here
The MySQL binary log records data modifications but does not include the user account that performed them. It is used for replication and point-in-time recovery, not for auditing user activity. While it can show what changes were made, it lacks the user context needed to identify the responsible account.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.