Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

In database forensics, which type of log records every transaction (including INSERT, UPDATE, DELETE) and allows reconstruction of database changes over time?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transaction log

Transaction logs (also called redo logs) record all changes to the database, enabling point-in-time recovery and auditing of data modifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Audit log

    Why it's wrong here

    Audit logs are security-focused records that capture events such as user authentications, privilege changes, and data access attempts, often for compliance purposes. However, they do not inherently record every transaction; their scope depends on configurable audit policies, and many database systems only log specific actions or queries that match predefined rules. Therefore, while an audit log can contain transaction information, it is not guaranteed to provide a complete, sequential record of every data modification.

  • ✗

    Error log

    Why it's wrong here

    Error logs record only exceptional conditions and system-level failures, such as internal errors, failed startup attempts, corrupted table events, or connection problems. They are not designed to track successful data manipulation operations like INSERT, UPDATE, or DELETE statements. Since normal transactions do not generate error entries, an error log fails to provide a record of each transaction and is therefore unsuitable for complete transaction logging.

  • ✓

    Transaction log

    Why this is correct

    The transaction log (also known as the redo log or write-ahead log) is the authoritative database component that sequentially records every data modification operation before it is committed to the main data files. In crash recovery, this log ensures ACID durability by enabling rollback of uncommitted transactions and replay of committed ones. Because it captures the before-and-after images (or logical changes) of all successful and incomplete transactions, it is the correct answer for a log that records every transaction.

  • ✗

    Slow query log

    Why it's wrong here

    Slow query logs are performance-tuning utilities that only record statements whose execution time exceeds a configurable threshold, such as long_query_time in MySQL. Fast-running transactions are completely omitted, and even slow SELECT statements may be logged, meaning the log is not a complete or accurate representation of all data modifications. Its purpose is to identify bottlenecks, not to provide a transactional audit trail, so it cannot satisfy the requirement of recording every transaction.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.