CHFI Mobile and Malware Forensics Practice Question
An analyst is investigating a potential data breach on an Android device. Which TWO artefacts are MOST useful for determining which third-party apps were installed and used? (Select TWO.)
⚠ Common exam trap
The CHFI exam often tests the misconception that a full system dump (dd image) is the most useful artefact for app analysis, when in reality the structured packages.xml and /data/data/ directory provide more direct and actionable evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
packages.xml file in /data/system/
The packages.xml file in /data/system/ records all installed packages, including third-party apps, their permissions, and installation metadata. The /data/data/ directory contains per-package subdirectories with application-specific data, confirming actual usage and stored data. Together, these two artefacts provide definitive evidence of which third-party apps were installed and used on the device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full system dump (dd image)
Why it's wrong here
A full dd image captures every block, including deleted data, but it is an acquisition method rather than a specific artefact identifying installed or used third-party apps. It is tempting because completeness aids court admissibility, yet targeted package and usage databases answer the question directly.
- ✓
packages.xml file in /data/system/
Why this is correct
packages.xml, located in /data/system/, records every installed package with metadata including installer, version and permissions. This persistent system-level record survives app removal, letting the analyst enumerate third-party installations and identify which were present during the breach window.
- ✗
Wi-Fi connection logs
Why it's wrong here
Wi-Fi connection logs record network associations and timestamps, indicating where a device connected rather than which third-party applications were installed or launched. They are tempting for placing a device at a location, but application inventory and usage require package-manager and usage-statistics artefacts.
- ✓
/data/data/ directory listing
Why this is correct
The /data/data/ directory listing reveals each installed app's private storage folder, named by package identifier, directly satisfying the requirement to determine which third-party apps were installed. On rooted or forensic images, this exposes package names absent from user-accessible areas, confirming installation even where usage evidence is limited.
- ✗
SMS database (mmssms.db)
Why it's wrong here
mmssms.db stores SMS and MMS message content, revealing communications but not the inventory or execution history of installed third-party applications. It is tempting because it is a well-known, easily parsed SQLite artefact, yet app-usage questions demand package listings and usage-statistics records instead.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.