Courseiva

CHFI Database and Application Forensics Practice Question

During a forensic investigation of a MongoDB database, the analyst needs to identify which user executed a particular write operation. Which MongoDB log or feature should the analyst examine?

⚠ Common exam trap

EC-Council often tests the misconception that the oplog or system log records user identity, when in fact only the audit log provides authenticated user attribution for database operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Audit log (auditLog)

The audit log (auditLog) is the correct source because it is specifically designed to record user authentication and database operations, including which user executed a write operation. MongoDB's audit system captures detailed events such as insert, update, and delete commands along with the authenticated user identity, making it the definitive forensic artifact for user attribution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Journal (journal directory)

    Why it's wrong here

    The MongoDB journal (journal directory) is a write-ahead redo log used exclusively for crash recovery, ensuring that committed writes survive an unclean shutdown by replaying the last checkpoint. Its records contain physical data-file changes and transaction identifiers, not the authenticated user, client IP, or logical operation that produced them. The journal is also truncated or deleted on clean shutdown, so it lacks the historical depth and attribution metadata required for forensic investigation of user actions.

  • ✗

    System log (mongod.log)

    Why it's wrong here

    The system log (mongod.log) captures server-level operational messages such as startup/shutdown, connection lifecycle, network errors, and severe database exceptions, with verbosity set by the administrator. It does not systematically record every CRUD operation or bind that operation to a specific authenticated user; even when profiling is enabled, the log entries lack structured fields like username, session ID, and full audit event types. Therefore, while the system log may help timeline reconstruction, it is not a reliable source for determining who performed a particular action.

  • ✓

    Audit log (auditLog)

    Why this is correct

    The audit log (auditLog) is the authoritative forensic source because MongoDB Enterprise's auditing feature, when enabled, emits structured events for user actions including authentication, schema changes, and select CRUD operations. Each audit record contains critical metadata such as the authenticated user (authUser), the exact timestamp, the operation type, and the source IP, enabling precise attribution. Its behavior can be tuned with auditFilter and operationTypes to capture the full scope of actions, making it indispensable for identifying what a user did within the database.

  • ✗

    Oplog (local.oplog.rs)

    Why it's wrong here

    The oplog (local.oplog.rs) is a capped collection used internally for replication, recording each write operation on the primary so secondaries can apply the same changes. Its documents contain the operation details (like database, collection, and update documents) but do not include the originating user, session token, or client address, because replication is mostly operation-based rather than user-based. Additionally, the oplog is a fixed-size circular buffer that continuously overwrites older entries, so historical data is lost quickly and cannot serve as a durable audit trail for user actions.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.