Courseiva

CHFI Mobile and Malware Forensics Practice Question

An Android forensic examiner performs a physical acquisition on a device. Which TWO of the following are typical artefacts that can be recovered from the /data/data/ directory on a non-rooted device if the acquisition method allows full file system access?

⚠ Common exam trap

EC-Council often tests the misconception that /data/data/ is inaccessible on non-rooted devices, but a physical acquisition with full file system access (e.g., via JTAG or chip-off) can read the raw NAND flash, allowing recovery of app data regardless of root status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

App-specific SQLite databases

Option D is correct because /data/data/<package_name>/ is the private sandbox for each installed app, and apps commonly store their structured data in SQLite databases (e.g., /data/data/com.example.app/databases/*.db), which a full file-system acquisition can recover. Option E is correct because Android apps persist key-value settings in SharedPreferences, stored as XML files under /data/data/<package_name>/shared_prefs/*.xml, which are likewise recoverable with full file-system access. Options A, B, and C are not typical artefacts of /data/data/: bootloader configuration resides in bootloader/partition areas (e.g., /misc, /bootloader), recovery mode logs are produced by the recovery partition and typically stored in /cache/recovery/, and kernel logs come from the kernel ring buffer accessed via dmesg or /proc/kmsg, not from the app data directory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Bootloader configuration

    Why it's wrong here

    Bootloader configuration is not present in /data/data/ because on Android devices bootloader parameters (e.g., locked/unlocked state, bootloader version, and partition metadata) reside in dedicated bootloader or misc partitions, not in the userdata volume. A physical acquisition images raw storage, but this artifact lives outside the app-private /data/data area. Therefore, an examiner should not expect to find bootloader settings there.

  • ✗

    Recovery mode logs

    Why it's wrong here

    Recovery mode logs are written to /cache/recovery/ (e.g., log, last_log, or last_install) rather than /data/data/, because the recovery boot image has its own storage context and does not mount userdata for regular app usage. Some newer devices may retain recovery logs under /data/recovery/ when the cache partition is unavailable, but they are never placed in individual app directories. Thus, these logs would not be encountered in /data/data/.

  • ✗

    Kernel logs

    Why it's wrong here

    Kernel logs are generated by the Linux kernel and are normally accessed through dmesg, /proc/kmsg, or pstore ramoops files such as /sys/fs/pstore/console-ramoops, not by applications in /data/data/. They reside in kernel memory or dedicated persistent storage regions and are protected by SELinux even on rooted devices. During a physical acquisition, kernel logs may be captured in the raw image, but they are not stored as files within app-private directories.

  • ✓

    App-specific SQLite databases

    Why this is correct

    App-specific SQLite databases are stored in /data/data/<package_name>/databases/ (or /data/user/0/<package>/databases/), making them a primary forensic target for messaging and browsing apps like WhatsApp, Facebook, or Chrome. A physical acquisition of the userdata partition preserves these files even when the app is closed or the device is locked, revealing chat history, contacts, search terms, and timestamps. This is why they are considered a cornerstone of Android mobile evidence.

  • ✓

    Shared preferences XML files

    Why this is correct

    Shared preferences XML files reside in /data/data/<package_name>/shared_prefs/ and commonly store app settings, login tokens, session IDs, and UI preferences in plaintext or weakly encoded form. These app-private files often contain authentication data that normal userspace access cannot read but that forensic acquisition can extract directly. Their presence in /data/data makes them essential for reconstructing user state and app behavior.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.