โ† All CHFI Flashcard Decks

Database Forensics Flashcards

6 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Database Forensics flashcards as text
  1. Which SQL Server system database stores metadata about all other databases on the SQL Server instance?

    Answer: master

    The master database stores all instance-level metadata including login accounts, endpoints, linked servers, and configuration settings.

  2. In database forensics, which log file type records every transaction and database modification for SQL Server?

    Answer: Transaction log (.ldf)

    The SQL Server transaction log (.ldf) records all transactions and database modifications, making it critical for forensic timeline reconstruction.

  3. What tool can a CHFI investigator use to read and analyze MySQL binary logs during a database forensic investigation?

    Answer: mysqlbinlog

    The mysqlbinlog utility reads MySQL binary log files, allowing investigators to reconstruct all SQL statements executed on the server.

  4. During a database forensics investigation, an investigator finds rows in a SQL Server table with no matching audit records. What should be checked first?

    Answer: The transaction log for direct inserts

    Direct inserts bypassing the application layer appear in the transaction log even if application-level audit triggers did not fire.

  5. Which Oracle database view provides information about all currently connected sessions and can help identify unauthorized access?

    Answer: V$SESSION

    V$SESSION is a dynamic performance view in Oracle that displays information about all current database sessions including username, logon time, and program.

  6. What is the primary forensic value of the SQL Server msdb database?

    Answer: Contains SQL Agent job history and backup/restore history

    The msdb database stores SQL Server Agent job history, backup and restore history, and Database Mail data, providing a timeline of automated activities.