Courseiva

CHFI Mobile and Malware Forensics Practice Question

After a factory reset on an Android device, a forensic examiner attempts to recover user data. Which of the following statements is most accurate regarding the recoverability of data?

⚠ Common exam trap

The CHFI exam often tests the misconception that a factory reset performs a full secure wipe, when in reality it only removes file system pointers and does not overwrite the underlying data, making recovery possible until overwritten.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Some user data may be recoverable from the /data partition if it has not been overwritten

A factory reset on Android typically performs a fast format of the /data partition, which only erases the file system metadata (e.g., ext4 journal and inode tables) but does not overwrite the actual data blocks. Therefore, user data may remain on the flash storage and be recoverable using forensic tools until those blocks are overwritten by new writes. This is why option A is correct: some user data may be recoverable from the /data partition if it has not been overwritten.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Some user data may be recoverable from the /data partition if it has not been overwritten

    Why this is correct

    Factory reset on Android typically reformats the /data partition by re-creating its filesystem metadata, which removes logical pointers to user files but does not automatically zero or erase every data block on the flash storage. As a result, files that occupied previously allocated blocks can remain physically intact until overwritten by subsequent writes, and forensic tools can carve these residuals. If device encryption is in use and the key is properly discarded, recovery becomes harder, but this is a separate mechanism and does not make the raw remnants inherently impossible to recover.

  • ✗

    Data in /data/data/ is securely wiped using TRIM commands, making recovery impossible

    Why it's wrong here

    TRIM commands only notify the flash controller that certain logical blocks are no longer allocated; the actual physical erasure is deferred to background garbage collection and may not occur at all on every eMMC/UFS implementation. Moreover, filesystem modifications caused by a factory reset often touch only a small set of metadata blocks, so most user blocks are never passed to TRIM at all. Therefore, describing TRIM as a secure ‘wipe’ of /data/data/ is misleading; data may still be recoverable from blocks that were not trimmed or erased.

  • ✗

    All user data is permanently destroyed and cannot be recovered

    Why it's wrong here

    A factory reset operates at the filesystem layer, clearing inode tables, journal structures, and partition mounting state, but it does not perform a full physical erasure of NAND flash. The same physical storage cells that held contacts, photos, and app data still contain their original bit patterns until a write or erase operation actually touches them. Even an encrypted device can retain ciphertext remnants that, while not immediately decryptable, are not equivalent to permanent destruction.

  • ✗

    Only Google account tokens are recoverable after a factory reset

    Why it's wrong here

    There is no mechanism in Android factory reset that selectively preserves Google account tokens while destroying all other user data; the reset process removes all active account credentials in the accounts database and often triggers deactivation server-side. Claiming that tokens are the only recoverable artifact ignores the many categories of residual data, such as deleted media, cached databases, and messaging app records, that remain in unallocated space. Google tokens, stored in /data/system/accounts.db or similar key stores, may be invalidated by the reset, so they are not even the most reliable or exclusive remnants available to experts.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.