Courseiva

CHFI Mobile and Malware Forensics Practice Question

A forensic examiner is analyzing an Android device that has been factory reset. Which artefact is MOST likely to persist after a factory reset, providing potential evidence of prior usage?

⚠ Common exam trap

The trap is that a factory reset does not completely erase all data; certain system-level identifiers like Google account artefacts survive because they reside on partitions that are not formatted during a standard reset. Candidates often assume all user-related data is wiped, but persistent partitions retain these identifiers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Google account artefacts

Google account artefacts, such as the Google Services Framework (GSF) ID and the device's Google Account (GAIA) ID, may persist after a factory reset because they are often stored on a dedicated persistent partition (e.g., /persist or /misc) that is not erased by a standard reset. Forensic tools can recover these identifiers from that partition, providing evidence of prior usage. This is unlike user-generated data such as SMS, Wi-Fi passwords, or app logs, which reside in the /data partition and are typically wiped.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Google account artefacts

    Why this is correct

    On modern Android builds, factory reset intentionally preserves Factory Reset Protection (FRP) data—the last verified Google account identifier (and often an authentication token sealed with device-bound keys) is retained in dedicated persistent storage or in Google's cloud-side device registry. Even if the userdata partition is reformatted, a forensic examiner can extract the FRP Google account from a physical image of protected/persistent blocks or obtain it via Google Takeout/Google Dashboard log retrieval, making this the only listed item that survives by design.

  • ✗

    App installation logs

    Why it's wrong here

    Package installation logs live in volatile system areas such as /data/log and /data/system/packages.xml, all within the userdata partition; a factory reset re-keys userdata encryption and recreates these files from scratch, so there is no surviving package-install history in a post-reset logical image. Although deleted blocks could theoretically be carved from raw flash, the package manager does not periodically sync such logs to cloud storage, so they are not a standard retained artefact.

  • ✗

    Deleted SMS messages

    Why it's wrong here

    SMS messages are stored in mmssms.db and other telephony databases under /data/data/com.android.providers.telephony, protected by FBE per-user encryption keys; factory reset destroys both the database files and their encryption keys, rendering the old content cryptographically unrecoverable from a logical acquisition. Recovering them would require either a pre-reset physical image and flash-level carving or an explicit Google One backup copy, neither of which is a routine consequence of a reset.

  • ✗

    Wi-Fi passwords

    Why it's wrong here

    Wi-Fi credentials are held in /data/misc/wifi/WifiConfigStore.xml (or wpa_supplicant.conf) and are encrypted with Android Keystore-backed keys; userdata wipe reformats /data/misc and deletes those key blobs, so saved networks do not persist past reset. Android does not include Wi-Fi password entries in normal cloud backups, unlike Google account data, and no system component writes Wi-Fi secrets to a durable partition, making their post-reset recovery effectively impossible.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.