Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

An investigator is analyzing a compromised MySQL database server. To determine the exact time and content of a suspect data exfiltration query, which MySQL log should be examined first, assuming it is enabled?

⚠ Common exam trap

A common misconception is that the binary log captures all queries, but it only captures data-changing statements (DML/DDL), not SELECTs, which are the primary vector for data exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

General query log

The general query log records every SQL statement received by the MySQL server, including SELECT queries used for data exfiltration. Since the investigator needs the exact time and content of the suspect query, this log provides a complete, chronological record of all client-sent statements, making it the primary source for identifying the exfiltration event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    General query log

    Why this is correct

    The general query log is the correct choice because it captures every SQL statement received from clients, including SELECT queries, regardless of whether they modify data or exceed performance thresholds. In a MySQL compromise, attackers often use SELECT statements to exfiltrate sensitive data, and this log provides a complete chronological record of those reads. Unlike the binary or slow query logs, it does not filter by data-change events or execution time, making it the only reliable artifact for detecting and reconstructing data theft via query activity.

  • ✗

    Error log

    Why it's wrong here

    The error log is not the right source because it is designed to record server-level operational events such as startup/shutdown messages, crash recovery, replication errors, and authentication failures, not the execution of client SQL queries. While it may contain clues about privilege escalations or connection issues, it does not log SELECT statements or other data-access operations that would reveal exfiltration. Therefore, relying on the error log would miss the actual SQL traffic that represents the data breach.

  • ✗

    Binary log

    Why it's wrong here

    The binary log is not the correct log for capturing data exfiltration because it only records events that change the database state, such as INSERT, UPDATE, DELETE, and DDL operations. SELECT statements, which are the primary vehicle for reading and extracting data, are never written to the binary log since they do not alter the data. Even if the attacker also modified data, the log would not show the complete set of exfiltrated records, and it would omit purely read-only theft.

  • ✗

    Slow query log

    Why it's wrong here

    The slow query log is inappropriate here because it only captures SQL statements that take longer than a configured time threshold, typically set in seconds or milliseconds. An attacker performing data exfiltration can run fast, efficient SELECT queries that complete quickly and thus never appear in this log. Even if some exfiltration queries were slow, the log would be incomplete and would not serve as a comprehensive record of all query activity, so it cannot substitute for the general query log.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.