Courseiva

CHFI Mobile and Malware Forensics Practice Question

A forensic examiner is analyzing an iOS device backup and wants to extract the user's iCloud-related artefacts. Which TWO of the following are typical sources of iCloud artefacts in an iTunes backup?

⚠ Common exam trap

EC-Council often tests the misconception that iCloud artefacts are found in user-facing databases like SMS.db or AddressBook.db, when in fact they reside in system configuration files like plists and the Keychain database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

com.apple.accounts.plist

Option B, com.apple.accounts.plist, is correct because this property list stores the device's configured account information, including iCloud account identifiers and settings, making it a primary source of iCloud-related artefacts in an iTunes backup. Option D, the Keychain database (keychain-backup.plist), is correct because iCloud credentials and tokens are protected within the keychain, and the backup's keychain-backup.plist preserves these secrets for forensic examination. Option A, AddressBook.db, is incorrect because it holds local contact data rather than iCloud account artefacts. Option C, Call_history.db, is incorrect because it contains call log records, not iCloud configuration or credential data. Option E, SMS.db, is incorrect because it stores text message data, which is unrelated to iCloud account artefacts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AddressBook.db

    Why it's wrong here

    AddressBook.db is the SQLite database that stores the user's contacts (people, phone numbers, email addresses) in an iOS backup. Contacts may include iCloud-synced entries, but the file itself neither contains iCloud account identifiers such as Apple ID, authentication tokens, nor the list of configured iCloud services. Therefore its presence does not establish that iCloud is enabled or reveal account credentials, making it an incorrect target for this specific query.

  • ✓

    com.apple.accounts.plist

    Why this is correct

    This preference plist (located at Library/Preferences/com.apple.accounts.plist in the backup's root domain) is the authoritative store for Accounts framework data, including iCloud (ACAccount). It records the user's Apple ID, account UUIDs, enabled iCloud services (e.g., Mail, Contacts, Calendars), and account status. A forensic examiner should parse this binary plist to identify iCloud account configuration and associated metadata, which directly answers the question.

  • ✗

    Call_history.db

    Why it's wrong here

    Call_history.db is a SQLite database containing call logs (timestamps, phone numbers, call duration) and holds no data about iCloud accounts or the device's sync configuration. During a backup, call history is stored under the 'Library/CallHistoryDB' path, and its schema has no tables referencing Apple ID or iCloud tokens. As a result, it is entirely unrelated to detecting iCloud account details and should not be examined for that purpose.

  • ✓

    Keychain database (keychain-backup.plist)

    Why this is correct

    keychain-backup.plist is the encrypted backup of the device's Keychain, which stores iCloud authentication tokens (e.g., com.apple.iCloud tokens), passwords, and certificates needed for iCloud services. Although its contents are protected by the backup password and require decryption with the device's UID-derived keys, the presence of iCloud-related keychain items can confirm iCloud usage. Therefore it is a valid source for iCloud account artifacts, but it complements rather than replaces the account listing in com.apple.accounts.plist.

  • ✗

    SMS.db

    Why it's wrong here

    SMS.db is the SQLite database for iMessage and SMS messages, storing conversation records and attachments, not iCloud account credentials. While iMessage is associated with an Apple ID, the database itself does not store the independent iCloud account configuration or authentication tokens; those remain in Keychain and the accounts plist. Examining SMS.db would reveal communications metadata only, making it irrelevant for verifying iCloud account setup.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.