โ† All CHFI Flashcard Decks

Database Forensics Flashcards

6 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Database Forensics flashcards as text
  1. Which technique allows a forensic investigator to recover deleted rows from a SQL Server database without a backup?

    Answer: Log file analysis using transaction log parser

    Deleted rows remain in the transaction log until the log is truncated, allowing forensic tools like ApexSQL Log to reconstruct and recover deleted data.

  2. In a PostgreSQL forensic investigation, which directory contains the server log files by default?

    Answer: $PGDATA/log

    PostgreSQL writes server log files to the $PGDATA/log directory by default, recording connections, errors, and optionally all SQL statements.

  3. What does the term 'database carving' refer to in forensic investigations?

    Answer: Recovering database records from raw disk images without a live database

    Database carving involves extracting database records and structures directly from raw disk images or unallocated space when the database system is unavailable.

  4. Which Oracle audit trail type stores audit records in OS files rather than within the database itself?

    Answer: OS audit trail

    The OS audit trail writes audit records to the operating system audit log, making them harder for a compromised DBA to tamper with.

  5. A forensic investigator needs to determine when a specific stored procedure was last modified in SQL Server. Which catalog view should they query?

    Answer: sys.objects

    The sys.objects catalog view contains a modify_date column that records the last modification timestamp for all database objects including stored procedures.

  6. What type of attack involves inserting malicious SQL code into a query to extract or manipulate database data, and is commonly investigated in CHFI database forensics?

    Answer: SQL injection

    SQL injection attacks insert malicious SQL statements into input fields to manipulate database queries, often leaving traces in web server logs and database logs.