Courseiva

CHFI Mobile and Malware Forensics Practice Question

A forensic examiner is analyzing an Android device that was factory reset. Which TWO artefacts or methods could the examiner use to potentially recover or identify data from before the reset?

⚠ Common exam trap

EC-Council often tests the misconception that a factory reset permanently destroys all data, but candidates must recognize that cloud-synced artifacts and physical extraction methods can recover pre-reset data, while logical methods (ADB, UI) are rendered useless by the reset.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyzing Google account artefacts synced to the cloud

Option D is correct because data synced to the user's Google account (e.g., Gmail, Contacts, Calendar, Drive, Photos, and Android backups) resides in Google's cloud infrastructure and is not erased by a local factory reset, so the examiner can obtain pre-reset artefacts via the account or legal process. Option E is correct because a physical extraction tool such as Cellebrite UFED reads the underlying flash memory (often via ISP, JTAG, or chip-off) and can recover residual data, including remnants in unallocated space that survive a factory reset if not securely wiped. Option A does not belong because ADB logical extraction only exposes data accessible to the running OS or a debug-enabled device, and a factory reset removes user data and typically disables USB debugging. Option B does not belong because ADB backup cannot recover deleted apps and requires debugging authorization that a reset device will not grant. Option C does not belong because manual UI examination only shows the post-reset state and cannot surface pre-reset data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing a logical extraction via ADB

    Why it's wrong here

    Logical extraction via ADB requires the device to have USB debugging enabled and the host computer authorized. After a factory reset, the device is in an unconfigured state, so USB debugging is disabled by default and the authorization is cleared, leaving ADB unable to communicate with the device to perform any extraction. Even if ADB could connect, a logical extraction only exposes the current filesystem, not residual deleted data, so it would be of little forensic value at this point.

  • ✗

    Recovering deleted apps via ADB backup

    Why it's wrong here

    An ADB backup command provides a snapshot of currently installed apps and their data, but it presupposes that the device has completed the setup wizard and that the user has granted backup permission to the debug bridge. A factory reset wipes the device profile, disables developer options, and clears the host authorization, so issuing `adb backup` would fail before any data transfer occurs, and it cannot recover deleted application data regardless.

  • ✗

    Examining the device manually through the UI

    Why it's wrong here

    Manual UI examination after a factory reset presents only the first-boot setup wizard with no user artifacts accessible, because the reset removed all user-installed applications, cached data, and account credentials. Browsing through the settings or launcher offers no residual data, as the device file systems have been reinitialized to "out-of-box" state, making this option forensically ineffective.

  • ✓

    Analyzing Google account artefacts synced to the cloud

    Why this is correct

    Analyzing the associated Google account's cloud artefacts is a valid approach because the user's sync history may contain contacts, calendar entries, Chrome browsing data, and app-specific backups that were uploaded prior to the reset. Cloud data is independent of the device's storage, so even though the device is wiped, the forensic examiner can obtain a trove of evidence by accessing the account with proper legal authority. This method does not depend on device configuration or flash-memory recovery, thus providing a reliable and often commercially supported avenue for evidence acquisition.

  • ✓

    Using a physical extraction tool like Cellebrite UFED

    Why this is correct

    A physical extraction using specialised tools like Cellebrite UFED can recover unallocated space and file-system remnants that survive a factory reset, because the reset performs a logical wipe rather than a cryptographic erase of every flash block. The success of this technique is however inconsistent and depends on the handset's memory chip, the Android version, and whether the device is equipped with full-disk encryption, so it is a viable but not guaranteed acquisition method.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A mobile forensic examiner is analyzing an Android device that has been factory reset. Which TWO of the following artefacts are MOST likely to still be recoverable after a factory reset? (Select TWO)

medium
  • ✓ A.SMS messages
  • B.Deleted applications' data
  • C.Call logs
  • ✓ D.Google account tokens
  • E.Photos stored in internal storage

Why A: SMS messages (A) are frequently recoverable after an Android factory reset because they are stored in SQLite databases such as mmssms.db within the user data partition, and a factory reset typically performs a logical wipe that deletes file references rather than securely overwriting the underlying NAND flash blocks, leaving residual data recoverable via physical acquisition or file carving. Google account tokens (D) can also survive a factory reset because they may be retained in protected or persistent storage areas, such as the /persistent partition or hardware-backed keystore/TrustZone regions, which are not always erased by a standard userdata wipe, allowing re-authentication artefacts to remain. Call logs (C) are not the best answer because, although they also reside in a SQLite database (calllog.db) in userdata, the question asks for the TWO MOST likely artefacts and SMS plus account tokens are the stronger, more consistently recoverable pair in this scenario. Deleted applications' data (B) is generally removed with the app's private data directory during the reset and is far less reliably recoverable. Photos stored in internal storage (E) are typically erased from the userdata partition during a factory reset and are not among the most likely recoverable artefacts compared with SMS and account tokens.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.