Courseiva

CHFI Mobile and Malware Forensics Practice Question

An iOS forensic examiner recovers a Keychain dump from an iPhone. Which of the following types of data is typically NOT stored in the iOS Keychain?

⚠ Common exam trap

EC-Council often tests the misconception that all sensitive user data (including messages) is stored in the Keychain, but the Keychain is strictly for credentials and secrets, not for bulk message content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SMS message content

The iOS Keychain is designed to store small, sensitive credentials such as passwords, keys, and certificates. SMS message content is stored in the SMS/MMS database (sms.db) under the protected /private/var/mobile/Library/SMS/ directory, not in the Keychain. Keychain items are encrypted per-app or per-service, whereas SMS messages are managed by the Messages app and stored in a SQLite database with its own encryption layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wi-Fi passwords

    Why it's wrong here

    Wi-Fi passwords are stored in the iOS Keychain as network passphrases, with service strings such as '%SSID' or 'AirPort' and an account field containing the Wi-Fi network name. A full keychain dump will therefore expose WPA/WPA2 pre-shared keys, which is why this option is not the correct answer. These entries usually belong to the AfterFirstUnlock protection class, but their presence in the dump is expected and does not surprise a forensic examiner.

  • ✗

    Safari saved passwords

    Why it's wrong here

    Safari saved passwords are Internet Passwords (genp) kept in the Keychain under website service names, commonly associated with 'com.apple.Safari' and iCloud Keychain for sync. When a keychain dump is decrypted with the proper bag keys, these credentials are readable as plaintext, so finding them is normal and expected. This option is wrong because it is exactly the kind of secret material the Keychain is designed to protect, not content that lives in an application database.

  • ✓

    SMS message content

    Why this is correct

    SMS message content is physically stored in the SQLite database located at /private/var/mobile/Library/SMS/sms.db, with message bodies in the 'message' table and multimedia payloads in an adjacent attachments directory. The iOS Keychain is reserved for small encrypted secrets—passwords, tokens, certificates, and private keys—and does not store conversational text. Even after recovering and decrypting a keychain dump, an examiner must turn to sms.db to obtain SMS or iMessage body text, so SMS content is the only listed item that is truly absent from a keychain dump and is therefore the correct answer.

  • ✗

    VPN credentials

    Why it's wrong here

    VPN credentials are stored in the Keychain as generic passwords or certificate-backed items, using service names tied to the VPN provider or to com.apple.cfnetwork for system VPN configurations. A keychain dump exposes pre-shared keys, user authentication passwords, and certificate identities needed to establish VPN sessions, meaning this option would appear in the recovered data. This option is wrong because VPN secrets are among the keychain's primary intended contents, not an unusual finding.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.