Courseiva

CHFI Database and Application Forensics Practice Question

During a database forensic investigation, an analyst recovers a MySQL binary log file (binlog.000012) from a compromised server. Which command should the analyst use to extract the actual SQL statements from this binary log in a human-readable format?

⚠ Common exam trap

EC-Council often tests the distinction between MySQL administrative utilities (mysqldump, mysqlcheck, mysqlimport) and the forensic-specific tool mysqlbinlog, exploiting the common misconception that any MySQL command with 'binlog' in its name can read binary logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

mysqlbinlog binlog.000012

The `mysqlbinlog` utility is specifically designed to parse MySQL binary log files and output the contained SQL statements in a human-readable format. Binary logs record all data-changing operations (e.g., INSERT, UPDATE, DELETE) in a proprietary binary format, so only `mysqlbinlog` can decode them back into readable SQL for forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    mysqldump --binlog binlog.000012

    Why it's wrong here

    mysqldump is a logical backup client that extracts schema and table data as SQL statements by querying the live database server, not by reading binary log files. It has no --binlog option for parsing binlog.000012, and even if an option with a similar name were present, its purpose is to produce a consistent database dump, not to decode statement-based or row-based binlog events. Therefore, it cannot serve as a forensic binary log reader.

  • ✗

    mysqlimport --binlog binlog.000012

    Why it's wrong here

    mysqlimport is a command-line utility designed solely to load delimited text files into tables using LOAD DATA INFILE syntax over the MySQL protocol. It expects an input file such as data.tsv containing column data, not a binary log; the --binlog argument is not a recognized option, and the tool cannot interpret the event headers, checksums, or base64 row images contained in binlog.000012. Running it against a binary log would fail immediately, and it has no capacity for forensic event parsing.

  • ✗

    mysqlcheck --binlog binlog.000012

    Why it's wrong here

    mysqlcheck is a table maintenance client used to CHECK, REPAIR, ANALYZE, and OPTIMIZE tables on a live MySQL server. It operates exclusively on database and table name arguments, performing integrity checks or repairs in place, and it lacks any code path for reading binary log files or extracting SQL statements from them. The --binlog option does not exist in mysqlcheck, and binlog.000012 is neither a database nor a table identifier, so the command is invalid both syntactically and semantically.

  • ✓

    mysqlbinlog binlog.000012

    Why this is correct

    mysqlbinlog is the official MySQL utility for reading binary log files and converting their events into human-readable SQL statements or, with appropriate options, into replayable SQL for database restoration. It supports statement-based, row-based, and mixed binlog formats, and it allows selective forensic analysis using time ranges, position ranges, and offset filters. In a database forensic investigation, running mysqlbinlog binlog.000012 reveals the exact transactional operations, timestamps, server IDs, and event sequence recorded in that log, enabling reconstruction of unauthorized changes or data exfiltration attempts.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.