Courseiva

CHFI Mobile and Malware Forensics Practice Question

A forensic examiner is analyzing an Android device for potential evidence of a specific app’s data. Which TWO locations within the device’s file system would MOST likely contain application-specific data?

⚠ Common exam trap

EC-Council often tests the misconception that `/system/app/` contains user app data, when in fact it only holds pre-installed APK files, not runtime or user-generated data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/data/data/<package_name>/

Option A, /data/data/<package_name>/, is correct because this is the primary internal storage location where an Android app's private data—such as SQLite databases, shared_preferences XML files, and cached files—is stored under its package name, accessible only with root or a forensic image. Option D, /sdcard/Android/data/<package_name>/, is correct because it is the app-specific external storage directory (on the emulated /sdcard partition) where apps commonly place user-generated files, downloads, and caches that are often recoverable without root. Option B, /recovery/, is not app-specific data; it holds the recovery partition image used for system recovery and OTA updates. Option C, / (root directory), is the top-level filesystem hierarchy containing system directories, not a location for a particular app's data. Option E, /system/app/, contains pre-installed system APK files, not the runtime data generated by a specific application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    /data/data/<package_name>/

    Why this is correct

    /data/data/<package_name>/ is the core of an Android app's private internal storage, residing on the /data partition. This sandboxed directory contains the app's databases (e.g., SQLite), shared preferences in XML files, cached web content, and other files the app reads/writes at runtime. Although protected by Linux UID permission barriers, forensic extraction via a full filesystem image or ADB backup (if backed up) can recover valuable user-generated data, cookies, and session tokens critical to an investigation. This is the primary location for evidentiary data produced by an application's own execution.

  • ✗

    /recovery/

    Why it's wrong here

    /recovery/ refers to the recovery partition—a dedicated bootable mode used for system updates, factory resets, and running diagnostic tools. It contains a lightweight Linux kernel and ramdisk (like the stock recovery or custom TWRP), not a mounted filesystem where app data is stored. While forensic tools may boot into recovery to bypass device locks and perform data extraction, the recovery partition itself holds no user or application files. Thus, it is not a source of app-specific evidence.

  • ✗

    / (root directory)

    Why it's wrong here

    The root directory (/) is the top-level mount point of the Android filesystem from which all other partitions and directories (e.g., /system, /data, /sdcard) are branched. It is not a writable storage area for applications; app data is always stored in subdirectories under dedicated mounted partitions, such as /data/data or /sdcard/Android/data. The root itself contains only the core OS structure (like /system, /proc, /dev), not user-installed app data. Therefore, examining the root directory without descending into /data yields no application-specific artifacts.

  • ✓

    /sdcard/Android/data/<package_name>/

    Why this is correct

    /sdcard/Android/data/<package_name>/ is the app-specific directory on the external or emulated shared storage partition. Apps write large media files, downloaded content, and optional caches here so they can be shared with other apps or accessed by the user via file managers. Unlike /data/data, this area is not sandboxed with per-app UID protections—an app with READ_EXTERNAL_STORAGE permission can potentially read another app's fragmented data here. Forensic examiners often recover images, videos, or exported databases from this location, but its contents are typically wiped when the app is uninstalled, unlike the internal data.

  • ✗

    /system/app/

    Why it's wrong here

    /system/app/ is the immutable system partition directory that contains the pre-installed APK (Android package) files for system applications such as Settings or the default browser. These are read-only system images and include only the code and resources of the app, not any runtime, user, or database content that would be generated when a user interacts with the app. Though a forensic examiner might analyze system app APKs for malicious static code, user-specific evidence is never found directly in /system/app. App data for system apps is still stored under /data/data/<package_name>/.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which Android file system location is MOST likely to contain user-installed app data, preferences, and cached information?

easy
  • A./vendor/
  • ✓ B./data/data/
  • C./system/
  • D./mnt/sdcard/

Why B: The /data/data/ directory on Android devices stores application-specific data for user-installed apps, including preferences (shared preferences XML files), databases, and cached information. This location is part of the internal storage partition and is sandboxed per app, ensuring that each app can only access its own data directory. It is the primary repository for runtime app data, making it the most relevant for forensic analysis of user-installed app artifacts.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.