Courseiva

CHFI Mobile and Malware Forensics Practice Question

An analyst is investigating a potential data breach on an Android device. Which TWO artefacts are MOST useful for determining which third-party apps were installed and used? (Select TWO.)

⚠ Common exam trap

The CHFI exam often tests the misconception that a full system dump (dd image) is the most useful artefact for app analysis, when in reality the structured packages.xml and /data/data/ directory provide more direct and actionable evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

packages.xml file in /data/system/

The packages.xml file in /data/system/ records all installed packages, including third-party apps, their permissions, and installation metadata. The /data/data/ directory contains per-package subdirectories with application-specific data, confirming actual usage and stored data. Together, these two artefacts provide definitive evidence of which third-party apps were installed and used on the device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Full system dump (dd image)

    Why it's wrong here

    A full dd image captures every block, including deleted data, but it is an acquisition method rather than a specific artefact identifying installed or used third-party apps. It is tempting because completeness aids court admissibility, yet targeted package and usage databases answer the question directly.

  • ✓

    packages.xml file in /data/system/

    Why this is correct

    packages.xml, located in /data/system/, records every installed package with metadata including installer, version and permissions. This persistent system-level record survives app removal, letting the analyst enumerate third-party installations and identify which were present during the breach window.

  • ✗

    Wi-Fi connection logs

    Why it's wrong here

    Wi-Fi connection logs record network associations and timestamps, indicating where a device connected rather than which third-party applications were installed or launched. They are tempting for placing a device at a location, but application inventory and usage require package-manager and usage-statistics artefacts.

  • ✓

    /data/data/ directory listing

    Why this is correct

    The /data/data/ directory listing reveals each installed app's private storage folder, named by package identifier, directly satisfying the requirement to determine which third-party apps were installed. On rooted or forensic images, this exposes package names absent from user-accessible areas, confirming installation even where usage evidence is limited.

  • ✗

    SMS database (mmssms.db)

    Why it's wrong here

    mmssms.db stores SMS and MMS message content, revealing communications but not the inventory or execution history of installed third-party applications. It is tempting because it is a well-known, easily parsed SQLite artefact, yet app-usage questions demand package listings and usage-statistics records instead.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.