Courseiva

CHFI Mobile and Malware Forensics Practice Question

A forensic investigator needs to analyze the keychain data from an iOS device backup. Which tool is specifically designed to decrypt and display iOS keychain contents?

⚠ Common exam trap

The CHFI exam often tests the misconception that general-purpose forensic tools like Cellebrite UFED or Magnet AXIOM can decrypt iOS keychain natively, when in fact only specialized tools like Elcomsoft Phone Breaker are designed for that specific task.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Elcomsoft Phone Breaker

Elcomsoft Phone Breaker is specifically designed to decrypt and display iOS keychain contents from backups, including passwords, tokens, and cryptographic keys. It leverages techniques such as brute-force, dictionary attacks, and GPU acceleration to recover the backup password, then extracts and decrypts the keychain data using its own implementation of the keychain decryption process, deriving the necessary encryption keys from the recovered backup password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Elcomsoft Phone Breaker

    Why this is correct

    Elcomsoft Phone Breaker is purpose-built for accessing iOS keychain contents, using a combination of iTunes/ramdisk backup decryption, keybag extraction, and GPU-accelerated brute-force or dictionary attacks against the backup password. It directly targets the cryptographic constructs (e.g., the device or backup keybag classes) to recover stored passwords, certificates, and tokens from keychain databases such as keychain-2.db. This is the only tool listed whose primary workflow is keychain decryption rather than general mobile data extraction.

  • ✗

    Cellebrite UFED

    Why it's wrong here

    Cellebrite UFED excels at physical, logical, and file-system extraction across thousands of mobile devices, and its strength lies in its broad hardware-based acquisition and automated parsing of app artifacts. While it can capture keychain databases during a physical extraction (especially if the device is jailbroken or runs a privileged agent), it does not itself perform the cryptographic keychain decryption; that typically requires external tools or the user's passcode. For a dedicated keychain decryption task, UFED is a general acquisition platform rather than a targeted decryption solution.

  • ✗

    Oxygen Forensic Detective

    Why it's wrong here

    Oxygen Forensic Detective is a comprehensive mobile forensics suite that emphasizes data linkage, visualization, and extraction from both devices and cloud services. Its 'Security Bypass' feature can unlock some devices using known exploits, but that bypass targets lock-screen access, not the decryption of individual keychain entries. Keychain decryption in Oxygen is essentially limited to reading data that is already decrypted after a successful unlock or to extracting protected data without the dedicated keybag-forensics approach used by specialized tools.

  • ✗

    Magnet AXIOM

    Why it's wrong here

    Magnet AXIOM is a cross-platform digital investigation platform that consumes data from many sources—mobile extractions, disk images, cloud accounts, and memory dumps—then processes artifacts into a unified, searchable case. Keychain items will appear in AXIOM only if they were already decrypted by the acquisition tool or if the cloud/jailbroken data provides them in plaintext; AXIOM itself has no built-in keychain decryption engine and does not attack the keybag or backup encryption. Its role is post-extraction artifact analysis and correlation, not cryptographic recovery.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.