CHFI Application, Email and Cloud Forensics Practice Question
In database forensics, which type of log records every transaction (including INSERT, UPDATE, DELETE) and allows reconstruction of database changes over time?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transaction log
Transaction logs (also called redo logs) record all changes to the database, enabling point-in-time recovery and auditing of data modifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit log
Why it's wrong here
Audit logs are security-focused records that capture events such as user authentications, privilege changes, and data access attempts, often for compliance purposes. However, they do not inherently record every transaction; their scope depends on configurable audit policies, and many database systems only log specific actions or queries that match predefined rules. Therefore, while an audit log can contain transaction information, it is not guaranteed to provide a complete, sequential record of every data modification.
- ✗
Error log
Why it's wrong here
Error logs record only exceptional conditions and system-level failures, such as internal errors, failed startup attempts, corrupted table events, or connection problems. They are not designed to track successful data manipulation operations like INSERT, UPDATE, or DELETE statements. Since normal transactions do not generate error entries, an error log fails to provide a record of each transaction and is therefore unsuitable for complete transaction logging.
- ✓
Transaction log
Why this is correct
The transaction log (also known as the redo log or write-ahead log) is the authoritative database component that sequentially records every data modification operation before it is committed to the main data files. In crash recovery, this log ensures ACID durability by enabling rollback of uncommitted transactions and replay of committed ones. Because it captures the before-and-after images (or logical changes) of all successful and incomplete transactions, it is the correct answer for a log that records every transaction.
- ✗
Slow query log
Why it's wrong here
Slow query logs are performance-tuning utilities that only record statements whose execution time exceeds a configurable threshold, such as long_query_time in MySQL. Fast-running transactions are completely omitted, and even slow SELECT statements may be logged, meaning the log is not a complete or accurate representation of all data modifications. Its purpose is to identify bottlenecks, not to provide a transactional audit trail, so it cannot satisfy the requirement of recording every transaction.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.