Database Forensics Flashcards
6 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Database Forensics flashcards as text
Which SQL Server feature, when enabled, records all login attempts including failed ones, and is critical for forensic investigations?
Answer: SQL Server Audit
SQL Server Audit tracks and logs SQL Server and database-level events including successful and failed login attempts, providing a forensic audit trail.
In database forensics, what information can be extracted from the MySQL ibdata1 file?
Answer: InnoDB tablespace data including deleted records not yet purged
The ibdata1 file is the InnoDB shared tablespace and contains table data, indexes, and potentially deleted records that have not yet been purged by InnoDB's background purge process.
What forensic technique involves comparing database schema versions to identify unauthorized structural changes?
Answer: Schema diffing
Schema diffing compares two versions of a database schema to detect unauthorized additions, modifications, or deletions of tables, columns, or stored procedures.
Which CHFI-relevant tool is specifically designed to recover and analyze SQLite database files commonly found on mobile devices and applications?
Answer: DB Browser for SQLite
DB Browser for SQLite allows forensic investigators to open, view, and recover data from SQLite database files, which are widely used in mobile apps and desktop applications.
During a forensic investigation, an analyst discovers that SQL Server error log entries have been deleted. Where else might evidence of malicious database activity be found?
Answer: Windows Event Logs and SQL Server transaction logs
Windows Event Logs record SQL Server service events and security events, while transaction logs record all data modifications, providing corroborating evidence even when error logs are deleted.
What is the significance of the SQL Server 'default trace' in a forensic investigation?
Answer: It captures database object changes, login failures, and DBCC events by default without configuration
SQL Server's default trace automatically captures key security and administrative events like object creation/deletion, login failures, and DBCC commands without requiring manual configuration.