Courseiva

CHFI · domain

Database and Application Forensics

This domain covers forensic examination of database management systems and application artifacts: transaction logs, binary logs, audit trails, and recovery behavior. Questions present recovered log entries, exhibits, or incident scenarios involving MongoDB, MySQL, and Microsoft SQL Server, asking you to identify what a log record proves, which feature captured it, and what data survives a destructive operation.

9 questions2 easy4 medium3 hard

Focused practice

Practice Database and Application Forensics questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Database and Application Forensics

Be able to read a recovered database log entry and state exactly what it proves: which user acted, when, and what changed. The critical skill is knowing which log or audit feature records user attribution, and that full recovery model plus an intact log backup allows recovery of dropped objects.

MongoDB logs and auditing features that attribute write operations to specific authenticated users

MySQL binary log event structure, including header timestamps and statement versus row-based entries

SQL Server full recovery model transaction log contents and point-in-time restore capability

Recovering dropped or deleted table data from SQL Server transaction log backups

Watch out for

Common Database and Application Forensics exam traps

  • ▸Reading a MySQL binary log timestamp as the event's execution time rather than the server's log-write time in the configured timezone.
  • ▸Assuming a DROP TABLE is unrecoverable under full recovery model when the log backup taken afterward still permits restoration.
  • ▸Confusing MongoDB connection, slow-query, or replication logs with the audit log that actually records the acting user.

Question index

All Database and Application Forensics questions (9)

Click any question to see the full explanation, or start a practice session above.

1

Refer to the exhibit. An analyst recovers this binary log entry from a MySQL server. What does the timestamp '190101 10:00:00' represent?

Medium
2

A forensic investigator is examining a compromised database server running Microsoft SQL Server 2019. The attacker gained access and executed several destructive queries. The investigator needs to determine the exact time and text of the malicious queries. The database is configured with the full recovery model, and transaction log backups are available. Which of the following should the investigator use to recover the query text?

Medium
3

You are a forensic investigator responding to an incident at a financial institution. The organization uses Microsoft SQL Server 2016 for its transaction processing system. The database is configured with full recovery model and transaction log backups are taken every 15 minutes. The incident response team has identified that an attacker gained access to the database server via compromised credentials and executed a series of malicious SQL statements, including data exfiltration and deletion of critical records. The time of the attack is estimated to be between 2:00 PM and 2:05 PM. The last full backup was taken at 12:00 AM (midnight) the same day. Transaction log backups are available for the entire day. The last transaction log backup before the attack was taken at 1:45 PM. The next transaction log backup after the attack was taken at 2:15 PM. The database is still online and being used by the business. Management wants to recover the database to a point just before the attack (2:00 PM) to minimize data loss, while preserving evidence for investigation. Which of the following actions should you take FIRST?

Hard
4

An organization uses Microsoft SQL Server 2019 with full recovery model. A database administrator accidentally executed a DROP TABLE statement. The transaction log was backed up immediately after the incident. Which forensic technique would allow the analyst to restore the dropped table?

Hard
5

During a database forensic investigation, an analyst recovers a MySQL binary log file (binlog.000012) from a compromised server. Which command should the analyst use to extract the actual SQL statements from this binary log in a human-readable format?

Medium
6

A forensic investigator is analyzing a Microsoft SQL Server instance that was compromised. The investigator wants to identify all login attempts that failed due to incorrect passwords. Which system function or view should be queried?

Easy
7

A forensic investigator is examining a MySQL database server that was compromised. The investigator needs to determine which user account was used to perform unauthorized modifications to a critical table. The MySQL server has the general query log enabled. Which of the following should the investigator review to find the user account associated with the modifications?

Easy
8

During a forensic investigation of a MongoDB database, the analyst needs to identify which user executed a particular write operation. Which MongoDB log or feature should the analyst examine?

Medium
9

Refer to the exhibit. A database administrator finds the above error log entries when attempting to start the MySQL service. The server was working fine yesterday. What is the most likely cause of this issue?

Hard

Frequently asked questions

What does the Database and Application Forensics domain cover on the CHFI exam?
Be able to read a recovered database log entry and state exactly what it proves: which user acted, when, and what changed. The critical skill is knowing which log or audit feature records user attribution, and that full recovery model plus an intact log backup allows recovery of dropped objects.
How many questions are in this domain?
This page lists all 9 Database and Application Forensics questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Database and Application Forensics questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-chfi EC-CHFI db app forensics Practice Questions