Courseiva

CHFI Mobile and Malware Forensics Practice Question

An Android device is found with factory reset performed. The forensic examiner wants to recover as much data as possible. Which of the following artefacts is MOST likely to survive a factory reset and provide useful evidence?

⚠ Common exam trap

The CHFI exam often tests the misconception that factory reset wipes all storage, including external SD cards, but the standard Android factory reset only targets internal partitions, leaving external storage untouched unless the user selects the additional 'Erase SD card' option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data stored on the external SD card

Factory reset wipes the /data partition, which includes /data/data/ (app data), AccountManager tokens, and system configuration files like wpa_supplicant.conf. However, external SD cards are typically not formatted during a factory reset because they are user-removable storage. Therefore, data stored on the external SD card (e.g., photos, videos, app backups) often survives intact and can provide valuable forensic evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deleted SQLite records from /data/data/

    Why it's wrong here

    A factory reset on Android invokes a wipe of the /data partition, typically using `rm -rf` or a format of the userdata block device. This irrecoverably deletes SQLite databases under /data/data/ (such as app databases and shared preferences) from the filesystem's perspective. While residual data might theoretically remain on NAND flash and be recoverable via chip-off or JTAG forensics, it is not accessible through standard file-system or deleted-record recovery tools. Therefore, deleted SQLite records are not considered present after a factory reset.

  • ✓

    Data stored on the external SD card

    Why this is correct

    An Android factory reset deliberately preserves the user-accessible external SD card (e.g., /storage/emulated/0/ or an actual removable microSD) because it is considered user data separate from the system and app data partitions. During a reset, only the /data, /cache, and sometimes /system partitions are wiped; the external SD card remains intact unless the user explicitly chooses to format it. Forensic examiners should image the external SD card immediately, as it often contains photos, documents, downloads, and application-exported files that survive the reset. This persistence makes external SD card data the only viable option for recovery.

  • ✗

    Google account authentication tokens stored in AccountManager

    Why it's wrong here

    Android's AccountManager stores Google account authentication tokens in the accounts.db database located at /data/system/accounts.db, which is part of the /data partition. A factory reset wipes this database along with all account credentials, sync tokens, and authentication state, effectively logging out all accounts and removing any cached OAuth tokens. Unlike other artifacts that might be recoverable from raw flash, these tokens are not stored externally and are deliberately cleared during the reset procedure. Thus, no authentication tokens remain accessible afterward.

  • ✗

    Wi-Fi passwords from wpa_supplicant.conf

    Why it's wrong here

    Wi-Fi credentials are stored in the wpa_supplicant.conf file, which resides in /data/misc/wifi/—a directory under the /data partition managed by the system. During a factory reset, this entire /data/misc directory is erased, including all saved Wi-Fi passphrases, network SSIDs, and Wi-Fi configuration caches. The reset process explicitly removes this file to ensure the device returns to an out-of-box state, so no legacy wpa_supplicant.conf is left behind. Consequently, Wi-Fi passwords are not recoverable from the file system after a reset.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.