Database Forensics Flashcards
6 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Database Forensics flashcards as text
Which technique allows a forensic investigator to recover deleted rows from a SQL Server database without a backup?
Answer: Log file analysis using transaction log parser
Deleted rows remain in the transaction log until the log is truncated, allowing forensic tools like ApexSQL Log to reconstruct and recover deleted data.
In a PostgreSQL forensic investigation, which directory contains the server log files by default?
Answer: $PGDATA/log
PostgreSQL writes server log files to the $PGDATA/log directory by default, recording connections, errors, and optionally all SQL statements.
What does the term 'database carving' refer to in forensic investigations?
Answer: Recovering database records from raw disk images without a live database
Database carving involves extracting database records and structures directly from raw disk images or unallocated space when the database system is unavailable.
Which Oracle audit trail type stores audit records in OS files rather than within the database itself?
Answer: OS audit trail
The OS audit trail writes audit records to the operating system audit log, making them harder for a compromised DBA to tamper with.
A forensic investigator needs to determine when a specific stored procedure was last modified in SQL Server. Which catalog view should they query?
Answer: sys.objects
The sys.objects catalog view contains a modify_date column that records the last modification timestamp for all database objects including stored procedures.
What type of attack involves inserting malicious SQL code into a query to extract or manipulate database data, and is commonly investigated in CHFI database forensics?
Answer: SQL injection
SQL injection attacks insert malicious SQL statements into input fields to manipulate database queries, often leaving traces in web server logs and database logs.