Courseiva

CHFI Mobile and Malware Forensics Practice Question

A forensic analyst is examining a SQLite database from an iOS device backup. The database contains a table named 'message' with columns 'ROWID', 'text', 'handle_id', and 'date'. This database is MOST likely part of which iOS system database?

⚠ Common exam trap

The CHFI exam often tests the misconception that 'message' tables are found in AddressBook.db or Calendar.db, but the specific column set (ROWID, text, handle_id, date) is unique to SMS.db in iOS forensics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SMS.db

The 'message' table with columns 'ROWID', 'text', 'handle_id', and 'date' is the core schema of the SMS.db database on iOS devices. This database stores iMessage and SMS/MMS messages, where 'handle_id' links to the 'handle' table for contact identifiers and 'date' stores the timestamp in Apple's absolute time (seconds since 2001-01-01). The presence of these specific columns confirms it is the SMS/Message database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SMS.db

    Why this is correct

    SMS.db is the iOS SQLite database that stores both SMS text messages and iMessage conversations. The 'message' table contains core evidence such as message text, ROWID, handle_id (linking to the phone number or email), date as Apple epoch nanoseconds, and the 'is_from_me' flag. The 'handle' table maps handles to actual addresses, and the 'service' column distinguishes between iMessage and SMS, making SMS.db the authoritative source for messaging forensics.

  • ✗

    call_history.db

    Why it's wrong here

    call_history.db is a separate SQLite database used by the iOS Phone application to record call metadata, not message content. Its 'call' table logs fields like date, duration, address (phone number), and call type (incoming, outgoing, missed). While a call log might correlate with messaging activity, it never contains SMS text bodies, so it is not the correct database for examining text messages.

  • ✗

    Calendar.db

    Why it's wrong here

    Calendar.db is the SQLite database that backs the iOS Calendar app, storing event details rather than communications. Tables such as CalendarItem and Calendar store event titles, start and end dates, notes, and participant info. These records are unrelated to SMS/iMessage content, and examining this database would yield no message text, making it inappropriate for message extraction.

  • ✗

    AddressBook.db

    Why it's wrong here

    AddressBook.db is the SQLite database for the iOS Contacts app, containing contact information such as names, phone numbers, email addresses, and related multi-value properties in tables like ABPerson and ABMultiValue. While contact identifiers may be referenced by message handle IDs, the AddressBook database stores no message bodies or user-created text conversations. Thus, it is not a source for SMS content.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.