CHFI Mobile and Malware Forensics Practice Question
A forensic examiner is analyzing an iOS device backup and wants to extract the user's iCloud-related artefacts. Which TWO of the following are typical sources of iCloud artefacts in an iTunes backup?
⚠ Common exam trap
EC-Council often tests the misconception that iCloud artefacts are found in user-facing databases like SMS.db or AddressBook.db, when in fact they reside in system configuration files like plists and the Keychain database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
com.apple.accounts.plist
Option B, com.apple.accounts.plist, is correct because this property list stores the device's configured account information, including iCloud account identifiers and settings, making it a primary source of iCloud-related artefacts in an iTunes backup. Option D, the Keychain database (keychain-backup.plist), is correct because iCloud credentials and tokens are protected within the keychain, and the backup's keychain-backup.plist preserves these secrets for forensic examination. Option A, AddressBook.db, is incorrect because it holds local contact data rather than iCloud account artefacts. Option C, Call_history.db, is incorrect because it contains call log records, not iCloud configuration or credential data. Option E, SMS.db, is incorrect because it stores text message data, which is unrelated to iCloud account artefacts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AddressBook.db
Why it's wrong here
AddressBook.db is the SQLite database that stores the user's contacts (people, phone numbers, email addresses) in an iOS backup. Contacts may include iCloud-synced entries, but the file itself neither contains iCloud account identifiers such as Apple ID, authentication tokens, nor the list of configured iCloud services. Therefore its presence does not establish that iCloud is enabled or reveal account credentials, making it an incorrect target for this specific query.
- ✓
com.apple.accounts.plist
Why this is correct
This preference plist (located at Library/Preferences/com.apple.accounts.plist in the backup's root domain) is the authoritative store for Accounts framework data, including iCloud (ACAccount). It records the user's Apple ID, account UUIDs, enabled iCloud services (e.g., Mail, Contacts, Calendars), and account status. A forensic examiner should parse this binary plist to identify iCloud account configuration and associated metadata, which directly answers the question.
- ✗
Call_history.db
Why it's wrong here
Call_history.db is a SQLite database containing call logs (timestamps, phone numbers, call duration) and holds no data about iCloud accounts or the device's sync configuration. During a backup, call history is stored under the 'Library/CallHistoryDB' path, and its schema has no tables referencing Apple ID or iCloud tokens. As a result, it is entirely unrelated to detecting iCloud account details and should not be examined for that purpose.
- ✓
Keychain database (keychain-backup.plist)
Why this is correct
keychain-backup.plist is the encrypted backup of the device's Keychain, which stores iCloud authentication tokens (e.g., com.apple.iCloud tokens), passwords, and certificates needed for iCloud services. Although its contents are protected by the backup password and require decryption with the device's UID-derived keys, the presence of iCloud-related keychain items can confirm iCloud usage. Therefore it is a valid source for iCloud account artifacts, but it complements rather than replaces the account listing in com.apple.accounts.plist.
- ✗
SMS.db
Why it's wrong here
SMS.db is the SQLite database for iMessage and SMS messages, storing conversation records and attachments, not iCloud account credentials. While iMessage is associated with an Apple ID, the database itself does not store the independent iCloud account configuration or authentication tokens; those remain in Keychain and the accounts plist. Examining SMS.db would reveal communications metadata only, making it irrelevant for verifying iCloud account setup.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.