Courseiva

CHFI Database and Application Forensics Practice Question

Exhibit

Refer to the exhibit.

```
MySQL Binary Log Entry:
# at 12345678
#190101 10:00:00 server id 1  end_log_pos 12345679 CRC32 0x12345678 	Query	thread_id=100	exec_time=0	error_code=0
SET TIMESTAMP=1546334400/*!*/;
DELETE FROM users WHERE id=5
/*!*/;
```

Refer to the exhibit. An analyst recovers this binary log entry from a MySQL server. What does the timestamp '190101 10:00:00' represent?

⚠ Common exam trap

The CHFI exam often tests the distinction between 'execution time on server' vs 'client send time' or 'commit time', and the trap here is that candidates confuse the binary log event timestamp with the client-side query submission time or the transaction commit time, which are recorded differently in MySQL's binary log format.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The time the DELETE statement was executed on the MySQL server

In MySQL binary logs, the timestamp in the 'Query' event header (e.g., '190101 10:00:00') records the server's local time when the statement began executing. This is the time the DELETE statement was actually processed by the MySQL server, not when the client sent it or when the log was written. The binary log captures the exact moment the server starts executing the query, making option A correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The time the DELETE statement was executed on the MySQL server

    Why this is correct

    The timestamp in the binary log entry records when the MySQL server executed the DELETE statement, as part of its statement-based or row-based logging. This is the server's authoritative clock at the moment the statement was processed, not when the client sent it or when the file was flushed. MySQL writes this event timestamp into the binary log header for replication and point-in-time recovery, reflecting execution time.

  • ✗

    The time the client sent the query to the server

    Why it's wrong here

    The timestamp reflects server-side processing, not the client's send time. Network latency, client-side batching, or queuing can delay the query arrival; the binary log captures when the server actually started executing the statement, after receiving it. So it cannot be used to measure client behavior or network transmission time.

  • ✗

    The time the binary log file was written to disk

    Why it's wrong here

    The binary log file is written as events are generated, but the event timestamp is set at execution time, independent of when the log file is physically flushed to disk. Disk I/O, buffering, and sync settings may cause a delay between event generation and file write. Therefore the timestamp does not indicate the write time to storage.

  • ✗

    The time the transaction was committed

    Why it's wrong here

    For a DELETE statement, particularly in non-transactional storage engines like MyISAM or with autocommit, there is no explicit transaction commit; the statement is immediately durable. Even in InnoDB, the binary log records the statement execution time, not the commit time, as a commit may occur later at the end of the transaction. Thus the timestamp is not about commit timing.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.