Courseiva

CCNA Mobile and Malware Forensics Questions

44 of 119 questions · Page 2/2 · Mobile and Malware Forensics · Answers revealed

76
MCQeasy

Which mobile forensics tool is specifically designed for physical extraction of iOS devices, including bypassing passcodes and extracting full file system images?

A.Oxygen Forensic Detective
B.Magnet AXIOM
C.Cellebrite UFED
D.GrayKey
AnswerD

GrayKey, developed by Grayshift, is a dedicated iOS forensic tool engineered specifically for physical extraction and passcode bypass. It exploits hardware and software vulnerabilities to gain full file-system access from locked iPhones/iPads, bypassing the Secure Enclave's retry limits. Law enforcement agencies use GrayKey for targeted deep extraction of iOS devices, making it the only option in this list uniquely designed for this purpose.

Why this answer

GrayKey is a specialized forensic tool developed by GrayShift that performs physical extraction on iOS devices, including bypassing passcodes and obtaining full file system images. It exploits hardware and software vulnerabilities in iOS to extract data, making it the correct choice for this specific task.

Exam trap

The trap here is that candidates often confuse Cellebrite UFED's broad device support with the specific ability to perform physical extraction and passcode bypass on iOS, but Cellebrite's iOS capabilities are more limited compared to GrayKey's specialized focus.

How to eliminate wrong answers

Option A is wrong because Oxygen Forensic Detective is a comprehensive forensic platform that supports logical and file system extractions for iOS, but it does not specialize in physical extraction or passcode bypass for iOS devices. Option B is wrong because Magnet AXIOM is a digital forensic tool that focuses on artifact analysis and logical extractions, not physical extraction or passcode bypass for iOS. Option C is wrong because Cellebrite UFED supports physical extraction for many devices, but for iOS, it primarily relies on logical extraction or using the device's backup, and does not consistently bypass passcodes for full physical extraction like GrayKey does.

77
Multi-Selecteasy

Which TWO of the following are anti-forensic techniques used by malware to evade detection?

Select 2 answers
A.Packing
B.Logging errors
C.Timestomping
D.Encryption of communication
E.Creating mutexes
AnswersA, C

Packing is a legitimate software distribution technique that malicious actors repurpose for anti-forensic effect. A packer compresses and often encrypts the original executable payload, embedding it within a decompressor stub, so the on-disk byte sequence no longer matches known malware signatures. At runtime, the stub unpacks the payload in memory, defeating static signature-based scans and complicating file-level triage by forensic investigators.

Why this answer

Packing (A) is an anti-forensic technique because it compresses or encrypts the malware's executable with a runtime unpacker stub, hiding strings, imports, and code from static analysis tools such as disassemblers and signature scanners. Timestomping (C) is anti-forensic because malware deliberately modifies file system timestamps (e.g., $STANDARD_INFORMATION vs. $FILE_NAME attributes in NTFS) to make malicious files appear older or to blend with legitimate files, frustrating timeline analysis. Logging errors (B) is not anti-forensic; it is a normal software development or debugging practice that actually leaves evidence behind.

Encryption of communication (D) is a defense-evasion/confidentiality technique for command-and-control traffic, not an anti-forensic technique targeting investigator artifacts. Creating mutexes (E) is a host-based evasion technique to prevent multiple malware instances from running, not a method to defeat forensic analysis.

Exam trap

The CHFI exam often tests the distinction between anti-forensic techniques (which actively hide or destroy forensic evidence) and general security mechanisms (like encryption of communication) that do not directly target forensic artifacts.

78
MCQmedium

A malware analyst is using a tool to monitor registry and file system changes during the execution of a suspicious binary. Which tool is specifically designed to take snapshots of the registry and file system before and after execution to identify changes?

A.Regshot
B.Cuckoo Sandbox
C.Process Explorer
D.Process Monitor
AnswerA

Regshot is a lightweight open-source utility that captures a baseline snapshot of the Windows registry and, optionally, the file system, then produces a second snapshot after the malware is executed. It compares the two snapshots and generates a detailed diff report, making it ideal for quickly identifying persistence locations, new files, and altered keys. Because it is not a real-time logger, it does not overwhelm the analyst with noise; instead, it gives a clean before-and-after view of system changes.

Why this answer

Regshot is a lightweight open-source tool designed specifically to compare registry hives and file system snapshots taken before and after executing a binary. It generates a detailed report of added, modified, or deleted keys and files, making it ideal for malware analysis to quickly identify persistence mechanisms or configuration changes.

Exam trap

The CHFI exam often tests the distinction between snapshot-based comparison tools (Regshot) and real-time monitoring tools (Process Monitor), leading candidates to confuse Process Monitor's live logging capability with the before-and-after snapshot functionality required by the question.

How to eliminate wrong answers

Option B is wrong because Cuckoo Sandbox is an automated dynamic malware analysis environment that executes binaries in a virtual machine and logs system calls, network traffic, and memory dumps, but it does not specialize in taking before-and-after registry and file system snapshots like Regshot does. Option C is wrong because Process Explorer is a task manager and process analysis tool from Sysinternals that shows detailed process information, handles, and DLLs, but it does not capture registry or file system snapshots for comparison. Option D is wrong because Process Monitor (Procmon) is a real-time monitoring tool that logs registry, file system, process, and thread activity as it happens, but it does not provide a before-and-after snapshot comparison; it requires manual filtering and analysis of a continuous event stream.

79
Multi-Selectmedium

A forensic examiner is analyzing an Android device for potential evidence of a specific app’s data. Which TWO locations within the device’s file system would MOST likely contain application-specific data?

Select 2 answers
A./data/data/<package_name>/
B./recovery/
C./ (root directory)
D./sdcard/Android/data/<package_name>/
E./system/app/
AnswersA, D

/data/data/<package_name>/ is the core of an Android app's private internal storage, residing on the /data partition. This sandboxed directory contains the app's databases (e.g., SQLite), shared preferences in XML files, cached web content, and other files the app reads/writes at runtime. Although protected by Linux UID permission barriers, forensic extraction via a full filesystem image or ADB backup (if backed up) can recover valuable user-generated data, cookies, and session tokens critical to an investigation. This is the primary location for evidentiary data produced by an application's own execution.

Why this answer

Option A, /data/data/<package_name>/, is correct because this is the primary internal storage location where an Android app's private data—such as SQLite databases, shared_preferences XML files, and cached files—is stored under its package name, accessible only with root or a forensic image. Option D, /sdcard/Android/data/<package_name>/, is correct because it is the app-specific external storage directory (on the emulated /sdcard partition) where apps commonly place user-generated files, downloads, and caches that are often recoverable without root. Option B, /recovery/, is not app-specific data; it holds the recovery partition image used for system recovery and OTA updates.

Option C, / (root directory), is the top-level filesystem hierarchy containing system directories, not a location for a particular app's data. Option E, /system/app/, contains pre-installed system APK files, not the runtime data generated by a specific application.

Exam trap

EC-Council often tests the misconception that `/system/app/` contains user app data, when in fact it only holds pre-installed APK files, not runtime or user-generated data.

80
MCQeasy

Which Android file system location is MOST likely to contain user-installed app data, preferences, and cached information?

A./vendor/
B./data/data/
C./system/
D./mnt/sdcard/
AnswerB

The /data/data directory (accessible as /data/user/0 on modern Android) is the standard, sandboxed root for each installed application's private data, including SQLite databases, SharedPreferences, cache files, and native libraries. Access is protected by Linux UID permissions—each app runs with a unique UID—so only the app itself and the root user can read these files. For forensic examiners, this is the primary source for recovering user app data such as chat logs, browser history, and app-generated artifacts.

Why this answer

The /data/data/ directory on Android devices stores application-specific data for user-installed apps, including preferences (shared preferences XML files), databases, and cached information. This location is part of the internal storage partition and is sandboxed per app, ensuring that each app can only access its own data directory. It is the primary repository for runtime app data, making it the most relevant for forensic analysis of user-installed app artifacts.

Exam trap

EC-Council often tests the misconception that user-installed app data is stored on the SD card (/mnt/sdcard/) because users commonly see app files there, but in Android's security model, private app data is strictly kept in /data/data/ and not on external storage.

How to eliminate wrong answers

Option A is wrong because /vendor/ contains proprietary firmware and system-level binaries provided by the device manufacturer, not user-installed app data. Option C is wrong because /system/ holds the Android operating system files (e.g., framework, core apps) and is read-only in normal operation; user-installed app data is never stored here. Option D is wrong because /mnt/sdcard/ (or /sdcard) is the external or emulated storage mount point for user-accessible files like photos and downloads, but it does not contain app-specific private data, preferences, or cached information that is sandboxed per app.

81
MCQhard

A malware analyst is examining a suspicious Windows executable. Running 'strings' reveals references to 'C:\Windows\System32\drivers\etc\hosts' and IP addresses 185.130.5.21 and 192.168.1.1. Dynamic analysis in a sandbox shows the binary modifies the hosts file and creates a mutex named 'Global\Mtx_Update'. Which behavioral indicator is MOST clearly associated with persistence?

A.Modifying the hosts file with an entry for 192.168.1.1
B.Connecting to IP 185.130.5.21 on port 443
C.Writing temporary files to %TEMP%
D.Creating the mutex 'Global\Mtx_Update'
AnswerA

The hosts file at %SystemRoot%\System32\drivers\etc\hosts is consulted by the Windows DNS resolver on every name-resolution attempt, so an entry mapping a domain to 192.168.1.1 changes system-wide resolution behavior even after a reboot. This is a persistent system-level configuration change that can silently redirect a target hostname to an attacker-controlled IP, enabling traffic interception, credential harvesting, or bypass of DNS-based defenses. Unlike transient runtime actions, this modification remains active until the file is edited or the entry is removed.

Why this answer

Modifying the hosts file to redirect a legitimate domain to 192.168.1.1 is a classic persistence mechanism: the malware ensures that every time the system resolves that domain, it points to the attacker-controlled IP, effectively hijacking network traffic persistently across reboots without needing to run at startup. This behavior directly maintains unauthorized control over name resolution, which is a hallmark of persistence.

Exam trap

EC-Council often tests the distinction between persistence (surviving reboot) and other behavioral indicators like mutex creation or network connections, so the trap here is confusing a mutex (used for single-instance control) with a persistence mechanism.

How to eliminate wrong answers

Option B is wrong because connecting to an external IP (185.130.5.21) on port 443 is a network communication indicator (C2 beaconing), not a persistence mechanism—it does not ensure the malware survives a reboot. Option C is wrong because writing temporary files to %TEMP% is a common execution artifact (e.g., dropping payloads or logs) but does not by itself guarantee the malware will re-execute after a system restart. Option D is wrong because creating a mutex (Global\Mtx_Update) is a synchronization primitive used to prevent multiple instances of the malware from running simultaneously; it does not provide any mechanism for automatic re-execution upon boot.

82
Multi-Selectmedium

A forensic investigator is analyzing a Windows system suspected of malware infection. Which THREE of the following are common persistence mechanisms that malware may use?

Select 3 answers
A.Scheduled Tasks via schtasks
B.Creating a Windows service
C.Adding an entry to the hosts file
D.Modifying the boot.ini file
E.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AnswersA, B, E

The Task Scheduler service can create tasks that run executables at specified times or system events, and schtasks.exe is a command-line interface for this. Malware can create hidden or named tasks that trigger on logon, idle, or unusual events, making them a robust persistence vector. Investigators should enumerate scheduled tasks via schtasks /query or the Task Scheduler API and compare against a known baseline.

Why this answer

Scheduled Tasks via schtasks (A) are a common persistence mechanism because malware can register a task with the Task Scheduler service to execute its payload at logon, on a schedule, or on system events, surviving reboots. Creating a Windows service (B) is also a classic persistence technique, since services configured with auto-start (e.g., via sc.exe create or the Service Control Manager) launch automatically at boot under a privileged account. The Run key at HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (E) is a well-known autostart location that Windows reads at user logon to launch listed programs, making it a favorite for malware persistence.

Adding an entry to the hosts file (C) is not a persistence mechanism; it only redirects DNS resolution and does not cause code to execute. Modifying boot.ini (D) is not applicable to modern Windows systems, which use the Boot Configuration Data (BCD) store, and boot.ini was used only on legacy BIOS-based Windows XP/2003 systems.

Exam trap

The CHFI exam tests the distinction between persistence mechanisms that cause automatic code execution on startup/logon and other system modifications (like hosts or boot.ini) that alter behavior but do not re-launch the malware. Windows services are explicitly a key persistence mechanism, but candidates sometimes overlook them because they blend in with normal system processes.

83
MCQmedium

An iOS forensic examiner recovers a Keychain dump from an iPhone. Which of the following types of data is typically NOT stored in the iOS Keychain?

A.Wi-Fi passwords
B.Safari saved passwords
C.SMS message content
D.VPN credentials
AnswerC

SMS message content is physically stored in the SQLite database located at /private/var/mobile/Library/SMS/sms.db, with message bodies in the 'message' table and multimedia payloads in an adjacent attachments directory. The iOS Keychain is reserved for small encrypted secrets—passwords, tokens, certificates, and private keys—and does not store conversational text. Even after recovering and decrypting a keychain dump, an examiner must turn to sms.db to obtain SMS or iMessage body text, so SMS content is the only listed item that is truly absent from a keychain dump and is therefore the correct answer.

Why this answer

The iOS Keychain is designed to store small, sensitive credentials such as passwords, keys, and certificates. SMS message content is stored in the SMS/MMS database (sms.db) under the protected /private/var/mobile/Library/SMS/ directory, not in the Keychain. Keychain items are encrypted per-app or per-service, whereas SMS messages are managed by the Messages app and stored in a SQLite database with its own encryption layer.

Exam trap

EC-Council often tests the misconception that all sensitive user data (including messages) is stored in the Keychain, but the Keychain is strictly for credentials and secrets, not for bulk message content.

How to eliminate wrong answers

Option A is wrong because Wi-Fi passwords are stored in the iOS Keychain as network credentials, accessible via the System Keychain. Option B is wrong because Safari saved passwords are stored in the Keychain under the iCloud Keychain or local Keychain for autofill. Option D is wrong because VPN credentials (e.g., L2TP, IPSec shared secrets, or certificate-based authentication) are stored in the Keychain as part of the VPN configuration payload.

84
MCQhard

After a factory reset on an Android device, a forensic examiner attempts to recover user data. Which of the following statements is most accurate regarding the recoverability of data?

A.Some user data may be recoverable from the /data partition if it has not been overwritten
B.Data in /data/data/ is securely wiped using TRIM commands, making recovery impossible
C.All user data is permanently destroyed and cannot be recovered
D.Only Google account tokens are recoverable after a factory reset
AnswerA

Factory reset on Android typically reformats the /data partition by re-creating its filesystem metadata, which removes logical pointers to user files but does not automatically zero or erase every data block on the flash storage. As a result, files that occupied previously allocated blocks can remain physically intact until overwritten by subsequent writes, and forensic tools can carve these residuals. If device encryption is in use and the key is properly discarded, recovery becomes harder, but this is a separate mechanism and does not make the raw remnants inherently impossible to recover.

Why this answer

A factory reset on Android typically performs a fast format of the /data partition, which only erases the file system metadata (e.g., ext4 journal and inode tables) but does not overwrite the actual data blocks. Therefore, user data may remain on the flash storage and be recoverable using forensic tools until those blocks are overwritten by new writes. This is why option A is correct: some user data may be recoverable from the /data partition if it has not been overwritten.

Exam trap

The CHFI exam often tests the misconception that a factory reset performs a full secure wipe, when in reality it only removes file system pointers and does not overwrite the underlying data, making recovery possible until overwritten.

How to eliminate wrong answers

Option B is wrong because TRIM commands are issued by the file system to the eMMC/NAND controller to mark blocks as unused, but they do not securely wipe data; they only allow the controller to garbage-collect blocks, and data remnants can often be recovered before physical erasure. Option C is wrong because a factory reset does not perform a secure erase or overwrite of all user data; it only removes file system pointers, leaving the underlying data intact until overwritten. Option D is wrong because not only Google account tokens but also other user data (e.g., app data, cached files, photos) may be recoverable from the /data partition after a factory reset.

85
MCQhard

A security analyst observes a suspicious process creating multiple mutexes with names like 'XxX_12345' and 'XxX_67890' and making outbound connections to an IP address 185.130.5.1 on port 443. Which behavioral indicator is MOST consistent with malware communication?

A.The process is performing data exfiltration via DNS tunneling
B.The process is attempting to spread to other machines via SMB
C.The mutexes indicate an attempt to prevent multiple instances, and outbound connections suggest C2 activity
D.The process is a legitimate application using mutexes for inter-process communication
AnswerC

Malware commonly creates specific named mutexes to ensure only one instance runs, preventing duplicate infections and making analysis harder; the presence of these mutexes is a behavioral indicator. Multiple outbound TLS connections to a fixed external IP on 443 are a classic command-and-control pattern, especially when the IP is a known suspicious address like 185.130.5.1, so combined these observations point to C2 activity.

Why this answer

The creation of mutexes with a consistent naming pattern (e.g., 'XxX_12345') is a classic anti-replication mechanism used by malware to ensure only one instance runs on a system, preventing conflicts and detection. The outbound connections to a specific IP on port 443 (HTTPS) are highly indicative of command-and-control (C2) communication, as malware often uses encrypted channels to blend in with legitimate traffic. Option C correctly identifies both the mutex's purpose (preventing multiple instances) and the network behavior (C2 activity), making it the most consistent with malware communication.

Exam trap

The CHFI exam often tests the misconception that any outbound connection on port 443 is automatically legitimate HTTPS traffic, but the trap here is that malware frequently uses this port for C2, and the mutex pattern is a key differentiator from benign software.

How to eliminate wrong answers

Option A is wrong because DNS tunneling involves encoding data in DNS queries/responses, typically on UDP port 53, not outbound HTTPS connections on port 443; the mutex names also have no relation to DNS. Option B is wrong because SMB propagation uses port 445 (or 139) for file and printer sharing, not port 443, and mutexes are not a standard mechanism for spreading via SMB. Option D is wrong because while legitimate applications do use mutexes for inter-process communication, the combination of suspicious mutex names (e.g., 'XxX_') and outbound connections to an external IP on a common C2 port (443) is not typical of benign software; legitimate apps rarely hardcode such patterns for external communication.

86
MCQmedium

A security analyst detects that a known malware sample writes to the registry key 'HKLM\SYSTEM\CurrentControlSet\Services\<malware>\ImagePath' and creates a service. This behavior is characteristic of which type of persistence mechanism?

A.Scheduled task
B.AppInit_DLLs
C.Startup folder entry
D.Windows service
AnswerD

The registry key HKLM\SYSTEM\CurrentControlSet\Services\<malware> is the canonical storage location for a Windows service definition, including the ImagePath to the executable, the Start value (e.g., 2 for AUTO_START), and the service Type. The Service Control Manager (SCM) enumerates these keys at system boot and launches the service according to its Start value, typically with SYSTEM privileges. This gives malware a reliable, auto-starting, system-level persistence mechanism that survives reboots and runs even before any user logs in. Therefore, the evidence strongly indicates the malware was installed as a Windows service.

Why this answer

The malware writes to 'HKLM\SYSTEM\CurrentControlSet\Services\<malware>\ImagePath' and creates a service, which is the exact mechanism for registering a Windows service. This persistence method ensures the malware runs automatically when the system boots, as the Service Control Manager (SCM) loads services based on this registry key. Option D is correct because this behavior directly corresponds to the Windows service persistence technique.

Exam trap

The CHFI exam often tests the distinction between registry-based persistence mechanisms; the trap here is that candidates confuse the 'Services' registry key with other common persistence locations like 'Run' keys or 'AppInit_DLLs', but the specific 'ImagePath' value under a service subkey uniquely identifies Windows service persistence.

How to eliminate wrong answers

Option A is wrong because scheduled tasks are configured via the Task Scheduler and stored in 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule' or XML files in '\Windows\System32\Tasks', not under the Services registry key. Option B is wrong because AppInit_DLLs persistence uses the 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs' registry value to load DLLs into every user-mode process, not by creating a service entry. Option C is wrong because the Startup folder entry involves placing a shortcut or executable in 'C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup' or the All Users startup folder, not modifying the Services registry hive.

87
MCQeasy

Which of the following is the primary purpose of performing static analysis on a suspicious binary?

A.Capturing network traffic generated by the binary
B.Observing the binary's runtime behaviour in a sandbox
C.Analysing the binary's code and structure without executing it
D.Modifying the binary to bypass anti-analysis techniques
AnswerC

Static analysis is the process of examining a binary without executing it, focusing on its structural and code-level characteristics. This includes parsing file headers (PE/ELF), analysing import and export tables, extracting readable strings, detecting packers, and disassembling or decompiling code into control flow graphs. The goal is to understand the program's functionality, capabilities, and potential vulnerabilities purely from its inert representation, making it safe for initial triage of unknown or malicious files.

Why this answer

Static analysis examines a binary's code and structure without executing it, allowing analysts to identify malicious indicators such as embedded strings, import tables, and cryptographic constants. This approach avoids triggering anti-analysis mechanisms that activate upon execution, making it a foundational step in malware forensics.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis, trapping candidates who confuse observing runtime behavior (dynamic) with examining code without execution (static).

How to eliminate wrong answers

Option A is wrong because capturing network traffic is a dynamic analysis technique that requires executing the binary to observe its communication, not static analysis. Option B is wrong because observing runtime behavior in a sandbox is dynamic analysis, which executes the binary and risks triggering anti-VM or anti-sandbox code. Option D is wrong because modifying the binary to bypass anti-analysis is an active evasion technique, not a purpose of static analysis; static analysis is non-invasive and does not alter the binary.

88
Multi-Selecteasy

Which TWO of the following are primary purposes of using the GrayKey tool in iOS forensics?

Select 2 answers
A.Perform static analysis of iOS malware
B.Decrypt iOS application binaries for analysis
C.Extract the full file system from a locked iOS device
D.Bypass the iOS passcode to gain access to the device
E.Create an encrypted iTunes backup
AnswersC, D

Once GrayKey successfully bypasses or brute-forces a lock screen passcode, one of its primary forensic functions is creating a full file system extraction from the iOS device's internal storage. This extraction preserves the user data partition, application sandboxes, and system files in a forensically sound manner for later analysis. Unlike logical backups, this captures deleted files and unallocated data, making it a core reason investigators deploy GrayKey.

Why this answer

Option C is correct because GrayKey is a hardware-based forensic tool designed to perform full file system extractions from iOS devices, including locked ones, providing investigators with a complete image of the device's data rather than just a logical backup. Option D is correct because a core function of GrayKey is passcode bypass — it uses brute-force and exploit techniques to defeat the iOS lock screen passcode, which is the prerequisite that enables the full file system extraction in option C. Options A and B are incorrect because GrayKey is not a static malware analysis platform nor a binary decryption tool; those tasks are handled by disassemblers and reverse-engineering suites such as IDA Pro, Ghidra, or Hopper.

Option E is incorrect because GrayKey does not create encrypted iTunes backups — that is the function of iTunes/Finder or libimobiledevice, and GrayKey's purpose is direct device extraction, not backup generation.

Exam trap

EC-Council often tests the distinction between 'bypassing the passcode' (option D) and 'extracting the file system' (option C) as separate but complementary purposes, leading candidates to incorrectly select only one when both are primary functions of GrayKey.

89
Multi-Selectmedium

An analyst is investigating a potential data breach on an Android device. Which TWO artefacts are MOST useful for determining which third-party apps were installed and used? (Select TWO.)

Select 2 answers
A.Full system dump (dd image)
B.packages.xml file in /data/system/
C.Wi-Fi connection logs
D./data/data/ directory listing
E.SMS database (mmssms.db)
AnswersB, D

packages.xml, located in /data/system/, records every installed package with metadata including installer, version and permissions. This persistent system-level record survives app removal, letting the analyst enumerate third-party installations and identify which were present during the breach window.

Why this answer

The packages.xml file in /data/system/ records all installed packages, including third-party apps, their permissions, and installation metadata. The /data/data/ directory contains per-package subdirectories with application-specific data, confirming actual usage and stored data. Together, these two artefacts provide definitive evidence of which third-party apps were installed and used on the device.

Exam trap

The CHFI exam often tests the misconception that a full system dump (dd image) is the most useful artefact for app analysis, when in reality the structured packages.xml and /data/data/ directory provide more direct and actionable evidence.

90
MCQmedium

During a malware analysis, a suspicious executable is detected. The analyst runs `strings` on the binary and finds references to `SOFTWARE\Microsoft\Windows\CurrentVersion\Run` and a URL `http://evil.com/beacon`. What does this indicate?

A.The malware is a file infector that modifies system binaries
B.The malware uses a mutex for synchronization
C.The malware establishes persistence and communicates with a remote server
D.The malware performs privilege escalation via a known vulnerability
AnswerC

The executable created a Run registry key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) to ensure it launches on every user logon, and it resolved and contacted an external URL, exfiltrating data or receiving commands. This combination of an autostart mechanism and a remote communication channel is the classic signature of a backdoor or RAT, making persistence and C2 the correct characterization of its behavior.

Why this answer

The presence of a registry key reference to `SOFTWARE\Microsoft\Windows\CurrentVersion\Run` indicates the malware is configured to launch automatically at system startup, establishing persistence. The embedded URL `http://evil.com/beacon` suggests the malware will make outbound HTTP requests to a remote command-and-control (C2) server for beaconing or data exfiltration. Together, these artifacts confirm persistence and remote communication, making option C correct.

Exam trap

EC-Council often tests the distinction between persistence mechanisms (like registry Run keys) and other malware behaviors (like file infection or privilege escalation), so candidates mistakenly associate any registry reference with file infection or confuse a URL with an exploit payload.

How to eliminate wrong answers

Option A is wrong because a file infector modifies system binaries (e.g., .exe or .dll files) to inject malicious code, but the `strings` output shows no evidence of file modification or infection routines—only a registry run key and a URL. Option B is wrong because a mutex is a synchronization object used to prevent multiple instances of malware from running, and no mutex name or reference is present in the provided strings; the artifacts shown are purely persistence and network indicators. Option D is wrong because privilege escalation exploits target vulnerabilities (e.g., CVE-XXXX) to gain higher access, but the strings reveal no exploit code, DLL injection paths, or UAC bypass techniques—only a registry autorun key and a beacon URL.

91
MCQhard

During dynamic analysis of a suspicious executable in Cuckoo Sandbox, the report shows that the process created a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run named 'WindowsUpdate' and dropped a file 'svchost.exe' in %AppData%. Which conclusion is MOST consistent with these indicators?

A.The executable is cleaning up after itself by deleting temporary files
B.The executable is a dropper that installs a rootkit
C.The executable is a legitimate Windows update component
D.The executable is attempting to establish persistence via a Run key and masquerading as a system process
AnswerD

Writing to HKCU\...\CurrentVersion\Run causes the payload to execute automatically at each user logon, satisfying the persistence requirement. Dropping svchost.exe into %AppData% exploits name masquerading, since the genuine svchost.exe resides in %SystemRoot%\System32, so analysts trusting the filename alone may overlook the rogue copy.

Why this answer

The creation of a Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run is a classic persistence mechanism that causes the executable to launch automatically at user logon. Dropping a file named 'svchost.exe' in %AppData% is a common masquerading technique, as the legitimate svchost.exe (Service Host) resides in C:\Windows\System32, not in the user's AppData folder. Together, these actions indicate the executable is establishing persistence and disguising itself as a trusted system process.

Exam trap

EC-Council often tests the distinction between persistence mechanisms and other malware behaviors, and the trap here is that candidates may confuse a dropper with a rootkit or assume any file named 'svchost.exe' is legitimate, ignoring the abnormal file path.

How to eliminate wrong answers

Option A is wrong because creating a Run key and dropping a file are actions that establish persistence, not cleanup; deleting temporary files would involve removing artifacts, not adding them. Option B is wrong because while the executable is a dropper (it drops a file), there is no evidence of a rootkit—rootkits typically hide processes or files via kernel-level hooks, not by simply adding a Run key and a masqueraded executable. Option C is wrong because legitimate Windows Update components do not write themselves to HKCU\Run or drop svchost.exe in %AppData%; Windows Update uses trusted system paths like C:\Windows\System32 and is managed by Windows Update service, not user-level Run keys.

92
Multi-Selectmedium

A forensic analyst is examining an Android device for evidence of a specific app's usage. Which TWO locations are MOST likely to contain app-specific data that can be recovered through a logical acquisition?

Select 2 answers
A./system/bin/
B./data/data/
C./mnt/sdcard/Android/data/
D./proc/
E./init.rc
AnswersB, C

/data/data/ is the definitive internal storage directory for each installed Android app, where the system creates a package-owned folder containing databases, shared_prefs, files, cache, and code-cache. This location is protected by the app's UID and Linux file permissions, and it is where applications persist user-generated content, login tokens, and SQLite databases that are prime forensic evidence. For both physical and logical acquisitions, this directory is the primary target for recovering app artifacts.

Why this answer

Option B (/data/data/) is correct because this is the primary internal storage path where Android stores each app's private data, including databases, shared preferences, and cache files, and on a rooted or debuggable device it can be captured during a logical acquisition. Option C (/mnt/sdcard/Android/data/) is correct because it is the app-specific external storage directory (also referenced as /sdcard/Android/data/ or /storage/emulated/0/Android/data/) where apps place user- and app-generated files such as downloads, media, and OBB assets that are recoverable via logical extraction. Option A (/system/bin/) is not app-specific data but the read-only system partition containing OS binaries and shell tools.

Option D (/proc/) is a virtual kernel filesystem exposing runtime process and system state, not persistent app evidence. Option E (/init.rc) is the Android init startup script defining boot-time services and actions, not user app data.

Exam trap

The CHFI exam often tests the misconception that /system/bin/ or /proc/ contain app-specific data because they sound like common storage locations, but in Android forensics, only /data/data/ and external storage paths like /mnt/sdcard/Android/data/ hold recoverable app artifacts during logical acquisition.

93
MCQmedium

A security analyst suspects a mobile device is infected with malware that exfiltrates data via DNS queries. Which tool or technique would be MOST effective for detecting this behavior during dynamic analysis?

A.PEiD to detect packers in the mobile app binary
B.Regshot to compare registry snapshots before and after execution
C.Process Monitor to observe registry and file system changes
D.Wireshark to capture and analyze network packets for anomalous DNS queries
AnswerD

Wireshark is a packet analyzer that captures raw frames and reassembles DNS messages, letting an analyst filter for dns.qry.name, spot repeated NXDOMAIN responses, or identify DGA subdomains typical of mobile malware. On Android, remote capture via USB tethering or a dedicated access point gives visibility into all app DNS lookups without modifying the device. Correlating query timing and volume can confirm an infection when static analysis is inconclusive.

Why this answer

D is correct because DNS exfiltration involves encoding stolen data into DNS query fields (e.g., subdomains or TXT records) and sending them to a malicious server. Wireshark captures and analyzes raw network packets, allowing the analyst to inspect DNS query payloads for anomalous patterns such as unusually long hostnames, high query volume, or queries to suspicious domains, which are hallmarks of DNS tunneling.

Exam trap

EC-Council often tests the misconception that dynamic analysis of malware behavior requires host-based monitoring (like Process Monitor) rather than network-based analysis, but for data exfiltration via DNS, packet capture is essential.

How to eliminate wrong answers

Option A is wrong because PEiD is a tool for detecting packers and compilers in Windows PE files, not for analyzing mobile app binaries or network behavior; it cannot capture DNS queries. Option B is wrong because Regshot compares Windows registry snapshots, which is irrelevant for mobile device analysis and does not monitor network traffic. Option C is wrong because Process Monitor (Procmon) monitors Windows registry, file system, and process activity on a local system, not network packets; it cannot detect DNS exfiltration over the wire.

94
MCQeasy

Which mobile forensic tool is commonly used to perform a physical extraction of an iOS device, including bypassing the lock screen on certain models?

A.Magnet AXIOM
B.GrayKey
C.Oxygen Forensic Detective
D.FTK Imager
AnswerB

GrayKey is a hardware-software system developed by Grayshift specifically for law enforcement and forensic use, designed to perform passcode bypass and physical extraction from iOS devices. It exploits bootrom or Secure Enclave vulnerabilities to derive the passcode and decrypt the file system, yielding a full filesystem image, keychain, and app data even from locked devices. This capability makes it the de facto standard for iOS physical extraction in many criminal investigations, distinguishing it from general-purpose mobile forensic platforms.

Why this answer

GrayKey is a specialized hardware tool designed by Grayshift that performs physical extraction of iOS devices, including bypassing the lock screen on certain models (e.g., iPhone 5 through iPhone X) by exploiting bootrom vulnerabilities or using brute-force techniques. It is widely used in law enforcement for forensic acquisition of iOS devices where logical extraction is insufficient.

Exam trap

EC-Council often tests the distinction between logical extraction tools (like Magnet AXIOM or Oxygen Forensic Detective) and hardware-based physical extraction tools (like GrayKey), leading candidates to mistakenly choose a familiar forensic suite that cannot bypass iOS lock screens.

How to eliminate wrong answers

Option A is wrong because Magnet AXIOM is a comprehensive digital forensics platform that supports logical and file system extractions from iOS devices but does not natively perform physical extraction or lock screen bypass; it relies on other tools (like GrayKey or checkra1n) for that capability. Option C is wrong because Oxygen Forensic Detective is a forensic suite that can extract data from iOS devices via logical or advanced logical methods, but it does not include hardware-based physical extraction or lock screen bypass; it depends on third-party tools or jailbreaks for deeper access. Option D is wrong because FTK Imager is a disk imaging tool for creating forensic images of storage media (e.g., hard drives, SD cards) and does not support mobile device extraction, let alone iOS physical extraction or lock screen bypass.

95
MCQeasy

During a mobile device investigation, an examiner needs to acquire the maximum amount of data from a locked iOS device without modifying it. Which acquisition type should be used?

A.Manual acquisition
B.Physical acquisition
C.Logical acquisition
D.File system acquisition
AnswerB

Physical acquisition is the most comprehensive forensic method, creating a bit-for-bit image of the device's raw flash memory. This allows recovery of deleted files, unallocated space, and hidden partitions that logical or file system methods would miss. On locked devices, specialized tools like GrayKey or Cellebrite UFED leverage hardware or bootrom exploits (e.g., checkm8) to bypass the lock screen and extract the full memory image without needing the user's passcode. Because it operates below the operating system layer, physical acquisition is the only method that can fully preserve and recover data from a locked device.

Why this answer

Physical acquisition is the correct choice because it creates a bit-for-bit copy of the entire flash storage, including the operating system, user data, and deleted file remnants, without relying on the iOS operating system to be unlocked or cooperative. This method bypasses the lock screen by exploiting hardware or software vulnerabilities (e.g., checkm8 bootrom exploit) or using advanced forensic tools (e.g., Cellebrite, GrayKey) to read the raw NAND memory, ensuring maximum data extraction while maintaining forensic integrity.

Exam trap

EC-Council often tests the misconception that logical acquisition is sufficient for locked devices because it can extract backups, but the trap is that logical acquisition still requires the device to be unlocked or have a trusted relationship established, whereas physical acquisition is the only method that can bypass the lock screen to capture the entire storage image.

How to eliminate wrong answers

Option A is wrong because manual acquisition requires the device to be unlocked and interactive, which is impossible with a locked iOS device and only captures visible data on the screen, not the full storage. Option C is wrong because logical acquisition only extracts files and databases accessible through the iOS operating system’s APIs (e.g., via iTunes backup or libimobiledevice), which requires the device to be unlocked and does not capture deleted data or system partitions. Option D is wrong because file system acquisition, while more detailed than logical, still requires the device to be unlocked (e.g., via jailbreak or trusted connection) and only retrieves the file system hierarchy, not the raw blocks of the storage, missing unallocated space and hidden partitions.

96
MCQhard

During dynamic analysis of a Windows malware sample, Process Monitor shows repeated writes to 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'. What does this behaviour indicate?

A.The malware is disabling Windows Defender
B.The malware is establishing persistence to run at system startup
C.The malware is modifying network configuration
D.The malware is performing log wiping
AnswerB

The Run key is a standard Windows auto-start repository: under HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run, each value specifies a command line that the Winlogon process executes when a user logs on. Malware writing a new value here with its full path is a classic persistence technique, ensuring the malicious process is re-launched after a reboot or logon. Dynamic analysis often catches this write because the sample modifies the registry at runtime to survive, not just to alter a one-time setting.

Why this answer

The registry key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' is a standard Windows autorun location. Malware writing to this key ensures that its executable is launched automatically every time the system boots, which is a classic persistence mechanism. Process Monitor capturing repeated writes confirms the malware is actively establishing this startup persistence.

Exam trap

EC-Council often tests the distinction between persistence mechanisms (like Run keys) and other malware behaviors (like disabling security or log wiping), so the trap here is that candidates confuse the Run key's purpose with system configuration changes or defensive countermeasures.

How to eliminate wrong answers

Option A is wrong because disabling Windows Defender typically involves modifying security center settings or stopping services (e.g., via 'sc stop WinDefend' or writing to 'HKLM\SOFTWARE\Policies\Microsoft\Windows Defender'), not writing to the Run key. Option C is wrong because modifying network configuration involves changes to TCP/IP parameters, DNS settings, or firewall rules (e.g., via netsh or registry keys under 'HKLM\SYSTEM\CurrentControlSet\Services\Tcpip'), not the Run key. Option D is wrong because log wiping involves clearing event logs (e.g., via 'wevtutil cl' or 'Clear-EventLog') or deleting log files, not writing to the Run registry key.

97
MCQeasy

In static malware analysis, what is the purpose of using a tool like PEiD?

A.To monitor registry changes during execution
B.To detect packers or compilers used in the PE file
C.To disassemble the binary into assembly code
D.To analyze network traffic generated by the malware
AnswerB

The tool in question is a static file inspector that examines a PE binary's section names, raw header fields, and byte patterns without executing it. By matching those signatures against known cryptors, packers, and compilers, it identifies protections such as UPX or ASPack, giving the analyst an immediate hint about obfuscation before deeper reverse engineering. That detection directly guides whether unpacking is necessary before disassembly.

Why this answer

PEiD is a static analysis tool that identifies packers, cryptors, and compilers embedded in Portable Executable (PE) files by scanning for known signatures in the file's entry point and section headers. This helps an analyst understand whether the malware is packed (obfuscated) and what tool was used to create or compress it, which is critical before attempting dynamic analysis or unpacking.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis tools, and the trap here is that candidates confuse PEiD with a disassembler or a runtime monitor, because they see 'analysis' and assume it covers all phases of malware examination.

How to eliminate wrong answers

Option A is wrong because monitoring registry changes during execution is a dynamic analysis technique, not static; tools like Regshot or Process Monitor are used for that purpose. Option C is wrong because disassembling a binary into assembly code is the function of a disassembler such as IDA Pro or Ghidra, not PEiD, which only identifies packers/compilers. Option D is wrong because analyzing network traffic generated by malware is a dynamic analysis task performed with tools like Wireshark or tcpdump, not a static analysis tool like PEiD.

98
MCQeasy

Which of the following is a key difference between static and dynamic malware analysis?

A.Static analysis executes the malware, dynamic does not
B.Static analysis requires an internet connection, dynamic does not
C.Static analysis examines code without execution, dynamic analysis executes the sample
D.Static analysis is always automated, dynamic is manual
AnswerC

This is the fundamental distinction between the two analysis categories. Static analysis inspects the binary's code and structure without ever executing it, using techniques like disassembly, decompilation, and string extraction to infer behavior. Dynamic analysis executes the sample in a monitored environment, capturing its actual runtime actions such as API calls, process injection, and file operations, which often reveals behaviors that static analysis alone cannot see.

Why this answer

Static malware analysis involves examining the malware's code (e.g., disassembly, strings, headers) without executing it, while dynamic analysis runs the sample in a controlled environment (e.g., sandbox, debugger) to observe its runtime behavior. Option C correctly captures this fundamental distinction: static analysis is code-centric and non-executional, whereas dynamic analysis is behavior-centric and executional.

Exam trap

The trap here is that candidates often confuse the terms 'static' and 'dynamic' by associating 'static' with 'not moving' (incorrectly thinking it means no analysis) or misremembering which one involves execution, leading them to pick Option A.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: static analysis does NOT execute the malware, while dynamic analysis does. Option B is wrong because neither analysis inherently requires an internet connection; dynamic analysis often uses simulated network services (e.g., INetSim) to avoid real internet traffic, and static analysis can be performed offline. Option D is wrong because both static and dynamic analysis can be automated (e.g., YARA rules for static, Cuckoo Sandbox for dynamic) or performed manually, so automation is not a distinguishing factor.

99
MCQeasy

Which of the following is an example of an anti-forensics technique used to hide malicious activity?

A.Timestomping
B.Running a sandbox
C.Creating a mutex
D.Generating a hash
AnswerA

Timestomping is a deliberate anti-forensic technique that alters file system timestamps — specifically the MAC times (modification, access, and change) — using tools like SetMACE or timestomp. By adjusting these metadata values to a false past or future date, an attacker destroys the temporal correlation that investigators rely on to reconstruct a sequence of events. This directly obfuscates the digital trail and impedes timeline analysis, making it a textbook example of anti-forensics.

Why this answer

Timestomping is an anti-forensics technique that deliberately modifies file timestamps (e.g., MAC times: Modified, Accessed, Created) using tools like `touch` on Linux or `SetFileTime` on Windows. By altering these timestamps, an attacker can hide the true timeline of malicious file creation, modification, or access, thereby evading forensic timeline analysis and making it appear that malicious activity occurred at a different time or was part of legitimate system operations.

Exam trap

The CHFI exam often tests the misconception that any technique used by malware (like creating a mutex) is automatically an anti-forensics technique, when in fact anti-forensics specifically targets the forensic process itself (e.g., data hiding, evidence destruction, or timeline manipulation).

How to eliminate wrong answers

Option B is wrong because running a sandbox is a security analysis technique used to execute suspicious code in an isolated environment to observe its behavior, not an anti-forensics technique to hide malicious activity. Option C is wrong because creating a mutex (mutual exclusion object) is a common programming construct used by both legitimate software and malware for synchronization or to prevent multiple instances, but it is not inherently an anti-forensics technique; while some malware uses mutexes as infection markers, this does not hide activity from forensic tools. Option D is wrong because generating a hash (e.g., MD5, SHA-1) is a standard integrity verification method used in forensics to ensure evidence has not been altered, not a technique to conceal malicious activity.

100
MCQmedium

A forensic analyst receives a mobile device that has been factory reset. Which of the following types of data is MOST likely to be recoverable using advanced forensic techniques?

A.Deleted text messages and call logs, but not app data
B.All user data, as factory reset only deletes file pointers
C.Google account tokens and cached credentials
D.No data is recoverable after a factory reset on modern devices
AnswerC

Google account tokens and cached credentials can remain recoverable because they are not always stored solely in the encrypted userdata partition. Some authentication tokens are cached in reserved flash areas, NVRAM, or the TrustZone secure world, which the factory reset routine may not fully overwrite. Advanced physical forensics, such as chip-off imaging and JTAG extraction, can recover these residual token blobs, and if combined with a known or brute-forced key, they may allow account access even though normal app and media data is destroyed.

Why this answer

A factory reset typically does not overwrite the flash memory where Google account tokens and cached credentials are stored. Advanced forensic techniques, such as chip-off or JTAG, can recover these remnants from the NAND flash memory, as the reset only marks the storage blocks as available for reuse without physically erasing the data.

Exam trap

EC-Council often tests the misconception that a factory reset is equivalent to a secure wipe, but in reality, it only deletes file pointers and leaves residual data in unallocated flash memory, which advanced forensic techniques can recover.

How to eliminate wrong answers

Option A is wrong because deleted text messages and call logs are also stored in unallocated flash memory and can be recovered alongside app data using advanced techniques, not exclusively excluded. Option B is wrong because a factory reset does not preserve all user data; it clears user data partitions and file pointers, but some residual data may remain in unallocated space, not the entire dataset. Option D is wrong because modern devices still leave recoverable data in unallocated NAND flash blocks after a factory reset, especially tokens and credentials, due to the lack of secure erase commands like eMMC sanitize being executed.

101
MCQeasy

Which of the following tools is designed specifically for dynamic analysis of malware by executing it in a controlled, isolated environment?

A.PEiD
B.Ghidra
C.Cuckoo Sandbox
D.IDA Pro
AnswerC

Cuckoo Sandbox executes suspect binaries inside an isolated virtual machine, then records process, file, registry and network activity. That runtime behavioural monitoring is dynamic analysis, distinguishing it from static tools that inspect code or signatures without executing the sample.

Why this answer

Cuckoo Sandbox is an open-source automated malware analysis system designed specifically for dynamic analysis. It executes suspicious files in a controlled, isolated environment (a virtual machine) and monitors their behavior, including system calls, file system changes, registry modifications, and network traffic, to produce a comprehensive report without risking the host system.

Exam trap

EC-Council often tests the distinction between static analysis tools (like PEiD, Ghidra, IDA Pro) and dynamic analysis sandboxes (like Cuckoo), so the trap is that candidates may confuse a debugger or disassembler (which can execute code step-by-step) with a fully automated, isolated sandbox environment.

How to eliminate wrong answers

Option A (PEiD) is wrong because it is a static analysis tool that detects packers, cryptors, and compilers in PE files by scanning signatures; it does not execute malware. Option B (Ghidra) is wrong because it is a reverse-engineering framework focused on static analysis and disassembly/decompilation of binaries, not on executing malware in an isolated environment. Option D (IDA Pro) is wrong because it is an interactive disassembler and debugger used for static and limited dynamic analysis (via its debugger), but it is not designed as a sandbox for automated, isolated execution of malware.

102
MCQmedium

During a mobile forensic investigation, an examiner finds that the seized iPhone is locked with a passcode but is running iOS 11. Which acquisition method should the examiner prioritize to obtain the most data without bypassing the passcode?

A.Physical acquisition using a JTAG tool
B.Logical acquisition via iTunes backup
C.File system acquisition using Cellebrite UFED
D.Manual acquisition by photographing the screen
AnswerB

iTunes backup can be initiated without passcode if device is trusted, and provides access to many artefacts including SMS, contacts, and call history.

Why this answer

For a locked iPhone running iOS 11, physical and file system acquisitions are typically blocked by hardware encryption and the Secure Enclave unless the passcode is bypassed. However, if the device has been previously trusted with a computer, a logical acquisition via iTunes backup can be performed without entering the passcode, as the trust relationship authorizes the backup. This method extracts the most data (contacts, messages, photos, etc.) without bypassing the passcode.

If no trust relationship exists, logical acquisition is not possible without the passcode, but the CHFI exam often assumes a previously trusted computer for this scenario.

Exam trap

The CHFI exam often tests the misconception that physical acquisition is always superior, but on modern iOS devices, logical acquisition via iTunes backup is the only viable method for locked devices without bypassing the passcode.

How to eliminate wrong answers

Option A is wrong because JTAG physical acquisition requires physical access to the device's circuit board and is typically used for older devices or when the device is disabled; on iOS 11, the Secure Enclave and full-disk encryption make JTAG impractical for locked devices without passcode bypass. Option C is wrong because file system acquisition using Cellebrite UFED on iOS 11 requires either a jailbreak or a known passcode to decrypt the file system; without bypassing the passcode, UFED cannot access the encrypted file system. Option D is wrong because manual acquisition by photographing the screen only captures visible data and is not a forensic acquisition method; it fails to retrieve deleted data, metadata, or data not currently displayed.

103
MCQmedium

During an iOS forensic examination, an analyst extracts an iTunes backup and finds a file named 'SMS.db'. Which of the following tools is BEST suited to parse and analyze this SQLite database for SMS and iMessage content?

A.GrayKey
B.Oxygen Forensic Detective
C.Cellebrite UFED
D.SQLite Browser
AnswerD

SQLite Browser is a free, open-source graphical tool that opens SQLite databases directly, allowing the examiner to browse table structures, execute SQL queries, and export results. For an iOS SMS.db file, it lets the analyst immediately inspect messages, timestamps, and associated metadata by running SELECT statements across the relevant tables. This makes it ideal for targeted database examination rather than relying on extraction hardware or a full analysis suite.

Why this answer

SQLite Browser is the best tool for parsing and analyzing the 'SMS.db' file because it is a free, open-source SQLite database viewer that allows direct querying and inspection of the database schema, tables, and records. Since 'SMS.db' is a standard SQLite database containing SMS and iMessage data in iOS backups, SQLite Browser provides the most straightforward and cost-effective method for manual forensic analysis without relying on proprietary extraction tools.

Exam trap

EC-Council often tests the misconception that commercial forensic suites like Cellebrite or GrayKey are always the best tools for every forensic task, when in fact a simple, free database browser is more appropriate for analyzing a standard SQLite file after extraction.

How to eliminate wrong answers

Option A is wrong because GrayKey is a specialized hardware tool for bypassing iOS passcodes and extracting full file system images, not for parsing individual SQLite databases like 'SMS.db' after extraction. Option B is wrong because Oxygen Forensic Detective is a comprehensive forensic suite that can parse SMS.db, but it is overkill for simply analyzing a single extracted database file and is not the 'best suited' tool for this specific task due to its cost and complexity. Option C is wrong because Cellebrite UFED is primarily a physical extraction and decoding tool for mobile devices, not a dedicated SQLite database browser; while it can parse SMS data from extractions, it is not the optimal choice for directly opening and querying an already extracted 'SMS.db' file.

104
MCQmedium

A security analyst is using Wireshark during a malware analysis session. The analyst observes a series of DNS queries to a domain 'malware-c2.example.com' every 60 seconds. This behavior is indicative of which malware characteristic?

A.Data exfiltration
B.DNS tunneling
C.Command and control (C2) communication
D.Propagation via network scanning
AnswerC

This is characteristic of command and control (C2) communication, specifically beaconing, where compromised hosts send regular, low-volume queries to a domain controlled by the attacker to receive instructions or report status. The periodic nature, consistent destination, and absence of payload data are hallmarks of a C2 beacon, distinguishing it from data transfer or network scanning. DNS is a preferred C2 channel because it often bypasses firewalls and proxy filters.

Why this answer

The periodic DNS queries to 'malware-c2.example.com' every 60 seconds are a classic heartbeat or beaconing mechanism used by malware to maintain persistent communication with its command and control (C2) server. This regular check-in allows the attacker to send commands or receive stolen data without requiring the malware to initiate a direct connection, which could be blocked by firewalls. The fixed interval and specific domain indicate a programmed C2 channel rather than a one-time data transfer or tunneling technique.

Exam trap

EC-Council often tests the distinction between DNS tunneling and C2 beaconing, where candidates mistakenly choose DNS tunneling because they see DNS queries, but the key differentiator is the regular, low-frequency pattern (beaconing) versus high-volume or encoded data in queries (tunneling).

How to eliminate wrong answers

Option A is wrong because data exfiltration typically involves sending stolen data (e.g., files, credentials) to an external server, often using HTTP POST, FTP, or DNS tunneling, but the periodic DNS queries alone do not indicate data transfer; they are just keep-alive signals. Option B is wrong because DNS tunneling encodes data within DNS query and response fields (e.g., subdomains or TXT records) to bypass network filters, but the described behavior—simple queries every 60 seconds—lacks the high volume or encoded payloads characteristic of tunneling. Option D is wrong because propagation via network scanning involves probing for vulnerable hosts using protocols like SMB, RDP, or SSH, not sending DNS queries to a fixed domain at regular intervals.

105
MCQeasy

Which of the following tools is BEST suited for performing static analysis of a malware binary to identify strings, headers, and imported functions without executing the file?

A.Cuckoo Sandbox
B.Any.run
C.Process Monitor
D.IDA Pro
AnswerD

IDA Pro is the industry-standard static interactive disassembler, capable of performing offline binary analysis without ever executing the code. It generates assembly-level listings, reconstructs control flow graphs, and can recover data structures, function boundaries, and API calls through its powerful FLIRT signatures and plugin extensibility. This is precisely the static analysis required for reverse engineering and vulnerability research, distinguishing it from dynamic sandboxes or runtime monitors.

Why this answer

IDA Pro is the correct choice because it is a disassembler and debugger specifically designed for static analysis of binary executables. It allows an analyst to examine strings, PE/ELF headers, and imported functions without executing the file, making it ideal for malware reverse engineering. In contrast, the other options require execution or focus on runtime behavior.

Exam trap

EC-Council often tests the distinction between static and dynamic analysis, and the trap here is that candidates confuse sandbox tools (Cuckoo, Any.run) or process monitors (Procmon) with static analysis because they are commonly used in malware forensics, but they all require execution.

How to eliminate wrong answers

Option A is wrong because Cuckoo Sandbox is an automated dynamic analysis system that executes the malware in a sandboxed environment, not a static analysis tool. Option B is wrong because Any.run is a cloud-based interactive malware analysis platform that also executes samples to observe behavior, not a static analyzer. Option C is wrong because Process Monitor (Procmon) is a real-time system monitoring tool that captures file system, registry, and process activity during execution, requiring the malware to run.

106
Multi-Selectmedium

An incident responder is analyzing a compromised Windows workstation. Which TWO artifacts would provide the STRONGEST evidence of a malware persistence mechanism?

Select 2 answers
A.Event log entry for user login
B.Registry Run key referencing a suspicious path
C.Scheduled Task entry pointing to a malicious executable
D.Network share access logs
E.Browser history showing download of a suspicious file
AnswersB, C

The Registry Run key (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) is a standard autorun location that launches specified executables at user logon. A suspicious path, particularly one outside standard program directories or with randomized naming, is a strong indicator of malware persistence. By writing a value here, the attacker ensures the payload executes automatically on every logon, making it a definitive persistence artifact. This is exactly the kind of evidence an incident responder would flag as critical.

Why this answer

Option B is correct because the Windows Registry Run keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run) are a classic autostart location that causes a program to execute automatically at user logon or system boot, so a Run key referencing a suspicious path is direct evidence of a persistence mechanism. Option C is correct because a Scheduled Task (stored under C:\Windows\System32\Tasks and managed via schtasks.exe or the Task Scheduler service) configured to launch a malicious executable is an explicit, recurring persistence technique that survives reboots and often runs with elevated privileges. Option A is not the strongest evidence because a user login event (e.g., Event ID 4624 in the Security log) only shows authentication activity and does not itself establish persistence.

Option D is not the strongest evidence because network share access logs record file access over SMB and do not demonstrate an autostart or persistence configuration. Option E is not the strongest evidence because browser history showing a suspicious download indicates possible initial infection or delivery, not an established persistence mechanism.

Exam trap

The CHFI exam often tests the distinction between infection vector artifacts (like browser history) and persistence mechanism artifacts (like Run keys or scheduled tasks), trapping candidates who confuse how malware arrives with how it survives a reboot.

107
MCQhard

An analyst extracts an iTunes backup from a Windows computer. The backup contains a file manifest.plist with cryptographic hashes. What is the primary purpose of these hashes in the backup process?

A.To compress the backup data
B.To verify the integrity of the backup files
C.To index the backup for faster searching
D.To encrypt the backup files
AnswerB

Computing a cryptographic hash (e.g., SHA-1 or MD5) of each backup file and comparing it against a known-good value confirms that the file's contents have not been modified, corrupted, or tampered with since the hash was created. This is the standard integrity-checking mechanism: any single-bit change in the file produces a completely different hash, allowing the analyst to detect accidental corruption or intentional alteration. In forensic examinations, verifying hashes ensures the extracted backup is an exact, trustworthy copy of the original evidence.

Why this answer

The cryptographic hashes in an iTunes backup's manifest.plist file are used to verify the integrity of the backup files. Each hash corresponds to a file in the backup, allowing the system to detect any corruption or tampering by comparing the stored hash against a newly computed hash of the file data.

Exam trap

EC-Council often tests the distinction between integrity verification (hashing) and confidentiality (encryption), so candidates may confuse the purpose of hashes with encryption or compression.

How to eliminate wrong answers

Option A is wrong because hashes do not compress data; compression is achieved through algorithms like zlib or LZMA, not cryptographic hashing. Option C is wrong because hashes are not used for indexing or searching; indexing is typically handled by separate metadata or database files (e.g., Manifest.db). Option D is wrong because hashes do not encrypt data; encryption in iTunes backups is performed using AES-256 with a key derived from the user's password, while hashes only provide integrity verification.

108
Multi-Selecthard

A malware analyst is performing dynamic analysis of a suspected trojan in a sandbox environment. Which of the following behaviours are strong indicators that the malware is establishing persistence on the infected system? (Select THREE.)

Select 3 answers
A.Creating a scheduled task that runs at system startup
B.Creating a Windows service named 'UpdateService'
C.Connecting to an IP address on port 443
D.Writing a value to HKCU\Software\Microsoft\Windows\CurrentVersion\Run
E.Creating a mutex named 'Global\MyMutex'
AnswersA, B, D

Scheduled tasks provide persistence by registering a trigger that activates the malware at system startup, before any user logs on. Using tools like schtasks.exe or by dropping an XML task into C:\Windows\System32\Tasks, an attacker can run arbitrary code with SYSTEM privileges on every boot. Because the task is stored on disk and loaded by the Task Scheduler service, it satisfies the definition of an auto-start extension point (ASEP) and is a common persistence mechanism.

Why this answer

Option A is correct because creating a scheduled task configured to trigger at system startup (e.g., via schtasks or the Task Scheduler COM API with a boot/logon trigger) is a classic persistence mechanism that ensures the trojan executes automatically after reboots. Option B is correct because registering a Windows service (e.g., through CreateService or sc.exe) allows the malware to be launched by the Service Control Manager at boot, providing durable, privileged persistence. Option D is correct because writing a value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run causes the referenced executable to be launched automatically at user logon, a well-known autostart persistence location.

Option C is not a persistence indicator; an outbound connection to port 443 typically reflects command-and-control or exfiltration activity, not survival across reboots. Option E is not a persistence indicator either; creating a named mutex such as Global\MyMutex is commonly used for single-instance enforcement or anti-analysis/anti-sandbox checks, not for maintaining execution on the host.

Exam trap

EC-Council often tests the distinction between persistence mechanisms and other malware behaviors (like network communication or inter-process synchronization), so the trap here is confusing network activity (C) or mutex creation (E) with persistence, when only startup-modifying actions (A, B, D) qualify.

109
Multi-Selecthard

During dynamic analysis of a malware sample, an analyst observes the following: creation of a mutex named `Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C}`, a registry key under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` named `WindowsUpdate`, and outbound TCP traffic to `203.0.113.5:443`. Which THREE of the following indicators of compromise (IoCs) should be documented?

Select 3 answers
A.Outbound TCP to `203.0.113.5:443`
B.SHA256 hash of the malware sample
C.Mutex name `Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C}`
D.File path `C:\Windows\System32\notepad.exe`
E.Registry key `HKCU\...\Run\WindowsUpdate`
AnswersA, C, E

The outbound TCP connection to 203.0.113.5 on port 443 is a classic command-and-control indicator observed during network-level monitoring. Even though this IP falls in the RFC 5737 TEST-NET-3 range often used for documentation, it represents the actual endpoint the malware contacted in the sandbox, demonstrating the value of capturing live connections for threat hunting.

Why this answer

Option A is correct because the observed outbound TCP connection to 203.0.113.5:443 is a network-based IoC that can be used for detection, blocking, and threat hunting, and the specific IP and port should be documented exactly as observed. Option C is correct because the mutex name Global\{9A2D7E1C-3F4B-4A5E-9B8C-1D2E3F4A5B6C} is a host-based IoC; mutexes are often unique to a malware family or campaign and can be used to identify infection or prevent reinfection. Option E is correct because the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate is a persistence IoC, since the Run key causes the named value to execute at user logon and should be documented for detection and remediation.

Option B is not among the observed dynamic behaviors listed in the scenario, even though a sample hash is useful context, and Option D is a legitimate Windows system file path that is not an IoC in this scenario.

Exam trap

The CHFI exam often tests the distinction between static IoCs (like file hashes) and dynamic IoCs (like network traffic, mutex names, and registry modifications) to see if candidates understand that dynamic analysis focuses on behavioral artifacts, not file-level attributes.

110
MCQmedium

An investigator is analyzing an Android device and finds a database file in /data/data/com.whatsapp/databases/msgstore.db. Which type of information is MOST likely stored in this database?

A.WhatsApp chat messages
B.System call logs
C.GPS location history
D.Contact list from the device
AnswerA

WhatsApp chat messages are stored in the app's dedicated SQLite database file named msgstore.db, located in /data/data/com.whatsapp/databases/. This database contains a `messages` table that holds the actual text content, sender/receiver identifiers, timestamps, and message types, making it the primary artefact for recovering chat history. Investigators can also recover deleted messages from free pages of the database file, or from the associated WAL/SHM files if present. Therefore, finding msgstore.db directly indicates WhatsApp chat messages as the relevant data.

Why this answer

The msgstore.db file in the WhatsApp package directory is the primary SQLite database that stores all WhatsApp chat messages, including text messages, media metadata, and message timestamps. This database is located at /data/data/com.whatsapp/databases/msgstore.db on Android devices and is a key artifact for forensic recovery of WhatsApp conversations.

Exam trap

EC-Council often tests the distinction between app-specific databases and system-level databases, and the trap here is that candidates confuse msgstore.db with a general-purpose database that might store contacts or location data, when in fact it is strictly for chat message storage within the WhatsApp application.

How to eliminate wrong answers

Option B is wrong because system call logs are stored in the Linux kernel's ring buffer or in /proc/ and /sys/ filesystem entries, not in an app-specific SQLite database like msgstore.db. Option C is wrong because GPS location history is typically stored in Google Play Services databases (e.g., /data/data/com.google.android.gms/databases/) or in the device's fused location provider, not in WhatsApp's msgstore.db (though WhatsApp may store location-sharing messages as part of chat content, the database itself is not a GPS history store). Option D is wrong because the contact list from the device is stored in the Contacts Provider database (e.g., /data/data/com.android.providers.contacts/databases/contacts2.db) or in WhatsApp's wa.db or axolotl.db, not in msgstore.db, which focuses on message threads.

111
Multi-Selecteasy

An Android forensic examiner performs a physical acquisition on a device. Which TWO of the following are typical artefacts that can be recovered from the /data/data/ directory on a non-rooted device if the acquisition method allows full file system access?

Select 2 answers
A.Bootloader configuration
B.Recovery mode logs
C.Kernel logs
D.App-specific SQLite databases
E.Shared preferences XML files
AnswersD, E

App-specific SQLite databases are stored in /data/data/<package_name>/databases/ (or /data/user/0/<package>/databases/), making them a primary forensic target for messaging and browsing apps like WhatsApp, Facebook, or Chrome. A physical acquisition of the userdata partition preserves these files even when the app is closed or the device is locked, revealing chat history, contacts, search terms, and timestamps. This is why they are considered a cornerstone of Android mobile evidence.

Why this answer

Option D is correct because /data/data/<package_name>/ is the private sandbox for each installed app, and apps commonly store their structured data in SQLite databases (e.g., /data/data/com.example.app/databases/*.db), which a full file-system acquisition can recover. Option E is correct because Android apps persist key-value settings in SharedPreferences, stored as XML files under /data/data/<package_name>/shared_prefs/*.xml, which are likewise recoverable with full file-system access. Options A, B, and C are not typical artefacts of /data/data/: bootloader configuration resides in bootloader/partition areas (e.g., /misc, /bootloader), recovery mode logs are produced by the recovery partition and typically stored in /cache/recovery/, and kernel logs come from the kernel ring buffer accessed via dmesg or /proc/kmsg, not from the app data directory.

Exam trap

EC-Council often tests the misconception that /data/data/ is inaccessible on non-rooted devices, but a physical acquisition with full file system access (e.g., via JTAG or chip-off) can read the raw NAND flash, allowing recovery of app data regardless of root status.

112
MCQmedium

During dynamic analysis of a malware sample, an analyst uses Process Monitor to monitor file system activity. The malware creates a file named 'C:\Users\Admin\AppData\Roaming\svchost.exe'. What does this likely indicate?

A.The malware is a legitimate Windows update
B.The malware is extracting an archive
C.The malware is cleaning up temporary files
D.The malware is attempting to achieve persistence by placing a copy in a user directory
AnswerD

By copying itself to a user-writable directory such as %APPDATA% or %LOCALAPPDATA% and renaming the copy to svchost.exe, the malware is likely staging itself for persistence — for example, by registering that executable path in a Run registry key or a scheduled task for automatic execution on boot. The AppData location is routinely writable by the unprivileged user, obviating the need for administrator privileges, while the system-process name is designed to evade casual user and security-tool inspection. In the dynamic sandbox, the mere creation of that file is a strong behavioral indicator of persistence planning, especially when followed by registry or task scheduler modifications.

Why this answer

The creation of a file named 'svchost.exe' in the user's AppData\Roaming directory is a classic persistence technique. By placing a copy of itself with the name of a legitimate Windows system process (svchost.exe) in a user-writable location, the malware aims to execute automatically at startup (e.g., via a registry Run key or scheduled task) while evading suspicion. This is not a legitimate Windows update, as system files reside in C:\Windows\System32, not in a user profile directory.

Exam trap

The CHFI exam often tests the misconception that any file named 'svchost.exe' is legitimate, but the key indicator is the path — a system process should never run from a user profile directory like AppData\Roaming.

How to eliminate wrong answers

Option A is wrong because legitimate Windows updates are delivered via Windows Update and stored in C:\Windows\SoftwareDistribution or System32, not created by malware in a user's AppData folder. Option B is wrong because extracting an archive would typically produce multiple files or a temporary extraction folder, not a single executable masquerading as a system process. Option C is wrong because cleaning up temporary files would involve deleting files (e.g., .tmp files) from Temp folders, not creating a new executable in AppData\Roaming.

113
MCQmedium

In malware static analysis, a PE file is examined. The section names include '.text', '.rdata', '.data', and '.rsrc'. The entry point is in the .text section. Which tool would be MOST appropriate to identify any packer that might be obfuscating the code?

A.strings
B.Ghidra
C.PEiD
D.IDA Pro
AnswerC

PEiD (Portable Executable Identifier) is purpose-built for static packer/cryptor/compiler detection by matching the file's entry-point bytes, section names, and structural features against a signature database. It identifies common packers like UPX, ASPack, and MEW, along with compilers, which directly answers the question of whether a PE is packed. This makes it the standard artifact triage tool, despite being dated and sometimes evaded by custom/modified packers.

Why this answer

PEiD is specifically designed to detect packers, cryptors, and compilers by scanning PE files for known signatures in the entry point and section headers. Since the question asks for identifying a packer that obfuscates code, PEiD's signature-based detection directly targets this need, unlike general-purpose disassemblers or string extractors.

Exam trap

EC-Council often tests the distinction between tools for packer detection versus general reverse engineering; the trap here is that candidates choose IDA Pro or Ghidra because they are powerful, but the question specifically asks for the *most appropriate* tool to *identify* a packer, not to analyze the unpacked code.

How to eliminate wrong answers

Option A is wrong because `strings` only extracts readable ASCII/Unicode sequences from a file and cannot identify packer signatures or obfuscation algorithms. Option B is wrong because Ghidra is a full reverse-engineering framework focused on disassembly and decompilation, not packer detection; it would require manual analysis to spot packer artifacts. Option D is wrong because IDA Pro is an interactive disassembler/debugger for deep code analysis, but it lacks automated packer signature scanning and is overkill for simply identifying a packer.

114
MCQmedium

In malware forensics, which of the following is an indicator of compromise (IoC) that can be used to detect a specific malware strain across multiple systems?

A.The file's size in bytes reported by the filesystem
B.The file's MD5 hash computed from its binary contents
C.The file's copyright metadata embedded in the PE header
D.The file's creation timestamp as recorded by the operating system
AnswerB

An MD5 hash is computed from the exact binary contents of the file, producing a fixed-length digest that acts as a fingerprint for that specific byte sequence; changing even a single bit results in a completely different digest. In malware forensics, matching a sample's MD5 against a threat intelligence database identifies a known malicious file with high confidence because the digest is directly derived from the bytes, not from mutable metadata. Although MD5 has known collision vulnerabilities, for identifying a particular captured sample it is still a standard and reliable indicator, with SHA-256 preferred for stronger assurance.

Why this answer

The MD5 hash of a file's binary contents is a unique cryptographic fingerprint that remains consistent across all copies of the exact same malware strain, regardless of where it is stored or what metadata the filesystem assigns. This makes it a reliable indicator of compromise (IoC) for identifying a specific malware sample across multiple systems, as the hash will match even if file names, sizes, or timestamps differ.

Exam trap

EC-Council often tests the misconception that file metadata like timestamps or sizes are reliable IoCs, when in fact they are easily altered or inconsistent across systems, whereas a cryptographic hash of the binary content provides a deterministic and verifiable identifier.

How to eliminate wrong answers

Option A is wrong because the file's size in bytes can vary due to padding, compression, or different file system cluster sizes, and multiple distinct malware strains can have identical file sizes, making it non-unique and unreliable as a specific IoC. Option C is wrong because copyright metadata embedded in the PE header is optional, easily stripped or modified by malware authors, and is not a consistent or trustworthy identifier across different samples of the same strain. Option D is wrong because the file's creation timestamp is set by the operating system at the time of file extraction or download, which varies per system and can be manipulated via timestomping, so it cannot uniquely identify a specific malware strain across multiple environments.

115
MCQmedium

During a forensic investigation of an Android device, the examiner uses ADB to extract data. Which command would create a full backup of the device's data partition, including app data and shared storage?

A.adb backup -f backup.ab -apk -shared -all
B.adb shell dd if=/dev/block/mmcblk0 of=/data/backup.img
C.adb pull /data/data/
D.adb restore backup.ab
AnswerA

The `adb backup -f backup.ab -apk -shared -all` command invokes Android's Backup Manager over ADB to create a non-root full logical backup, writing an Android Backup (AB) archive that contains installed APKs (-apk), shared/sdcard data (-shared), and all application data (-all). In forensic triage, this is the correct method to capture user-visible app data without altering the device's system partition, although it cannot retrieve protected app-private files from apps that disable backup or obtain deleted data. The resulting backup.ab can later be parsed with tools like Android Backup Extractor (abe) to reconstruct app content for analysis.

Why this answer

The `adb backup -f backup.ab -apk -shared -all` command creates a full Android backup that includes all apps and their data (via `-all`), includes APK files (via `-apk`), and includes shared storage (via `-shared`), outputting a single `.ab` file. This is the standard ADB method for non-rooted devices to capture a comprehensive logical backup of app data and shared storage.

Exam trap

The CHFI exam often tests the distinction between backup creation (`adb backup`) and restoration (`adb restore`), or between logical backups (ADB backup) and physical imaging (`dd`), leading candidates to confuse the purpose of each command.

How to eliminate wrong answers

Option B is wrong because `adb shell dd if=/dev/block/mmcblk0 of=/data/backup.img` attempts to create a raw block-level image of the entire device (mmcblk0), which requires root access and is not a standard ADB backup command; it also writes to a path that may not be writable without root. Option C is wrong because `adb pull /data/data/` only copies the app-specific data directory, missing shared storage and system data, and typically requires root access on modern Android devices due to permissions. Option D is wrong because `adb restore backup.ab` is used to restore a backup, not to create one, and thus does not extract data from the device.

116
MCQmedium

During an iOS forensic analysis, an examiner recovers the Keychain data from a backup. Which type of information is commonly stored in the iOS Keychain and can be extracted during analysis?

A.Text message content and attachments
B.Call log timestamps and durations
C.Contact photos and thumbnails
D.Wi-Fi passwords and website login credentials
AnswerD

Wi-Fi passwords and website login credentials are exactly the kind of secrets the iOS Keychain is designed to protect, stored as generic passwords and internet passwords in encrypted keychain databases. Each Keychain item includes metadata such as the service name, account name, and access group, and is encrypted with a key hierarchy that ties to the device's passcode via the Secure Enclave. During forensic acquisition, an examiner can use tools to decrypt the keychain or extract keychain plists from a file system image, which is why these credentials are the correct item to associate with Keychain analysis.

Why this answer

The iOS Keychain is a secure, encrypted database designed to store sensitive user credentials and secrets. Wi-Fi passwords and website login credentials are explicitly stored in the Keychain to protect them from unauthorized access, making them recoverable during forensic analysis of a backup.

Exam trap

The CHFI exam often tests the misconception that the Keychain stores all app data or media, when in fact it is strictly limited to credentials, tokens, and secrets, while other data types reside in separate databases.

How to eliminate wrong answers

Option A is wrong because text message content and attachments are stored in the SMS/MMS SQLite database (sms.db) and the attachments directory, not in the Keychain. Option B is wrong because call log timestamps and durations are stored in the CallHistory.storedata SQLite database, not in the Keychain. Option C is wrong because contact photos and thumbnails are stored in the AddressBook framework's SQLite database (AddressBook.sqlitedb) and the filesystem, not in the Keychain.

117
MCQmedium

An Android device is seized as evidence. The screen is locked with a PIN. Which tool or method is MOST appropriate for acquiring a physical image of the device without bypassing the lock screen, assuming the device is rooted?

A.Boot into recovery mode and use ADB to dd the userdata partition
B.Use Cellebrite UFED with a lock screen bypass exploit
C.Remove the microSD card and image it separately
D.Perform an ADB backup to obtain app data only
AnswerA

Booting into recovery mode bypasses the Android OS and its lock screen, so ADB access does not require user authorization, screen unlock, or USB debugging approval. With a rooted device already granting elevated privileges, issuing dd against the /dev/block/.../userdata path performs a block-level physical acquisition of the entire internal userdata partition, including encrypted blobs or files, which is exactly what the question requires. This method is correct because it captures the full internal storage image without needing to unlock the screen or install any bypass, and it preserves deleted data blocks for forensic analysis.

Why this answer

Booting into recovery mode on a rooted Android device allows you to use ADB to execute the `dd` command, which can create a bit-for-bit physical image of the userdata partition without needing to bypass the lock screen. Since the device is rooted, you have the necessary privileges to read the raw block device, and recovery mode ensures the filesystem is not mounted, preventing data corruption during acquisition.

Exam trap

EC-Council often tests the distinction between physical and logical acquisition methods, and the trap here is that candidates may choose ADB backup (Option D) thinking it is a valid physical acquisition, when in fact it only captures a logical subset of data and cannot recover deleted or system-level artifacts.

How to eliminate wrong answers

Option B is wrong because Cellebrite UFED with a lock screen bypass exploit is designed to bypass the lock screen, which contradicts the question's requirement of not bypassing the lock screen; additionally, such exploits may not be available or reliable for all devices. Option C is wrong because removing the microSD card and imaging it separately only captures external storage, not the internal userdata partition where the majority of forensic evidence (e.g., app data, messages) resides, and it does not acquire a physical image of the device's internal storage. Option D is wrong because an ADB backup only extracts app data via Android's backup mechanism, which is a logical acquisition that does not capture deleted data, system files, or the full physical image of the userdata partition.

118
MCQeasy

Which tool is specifically designed for performing physical extraction of iOS devices and is widely used by law enforcement for bypassing passcode restrictions on modern iPhones?

A.Cellebrite UFED
B.GrayKey
C.Magnet AXIOM
D.Oxygen Forensic Detective
AnswerB

GrayKey is a purpose-built hardware/software appliance engineered exclusively for iOS forensic physical extraction and passcode bypass. It connects to the device's Lightning port and performs automated brute-force attacks against the passcode, including techniques that leverage the device's secure enclave vulnerabilities to allow full filesystem acquisition. This focused capability, combined with high success rates on passcode-protected iPhones, is precisely why law enforcement agencies deploy GrayKey rather than general-purpose mobile tools for physical extraction.

Why this answer

GrayKey is specifically designed for physical extraction of iOS devices, leveraging advanced techniques to bypass passcode restrictions on modern iPhones, including those with Secure Enclave and full-disk encryption. It is widely adopted by law enforcement for its ability to perform brute-force attacks on the device's passcode without triggering the auto-wipe feature, making it the correct answer.

Exam trap

The CHFI exam often tests the distinction between general-purpose forensic suites (like Cellebrite UFED or Magnet AXIOM) and specialized hardware tools (like GrayKey) that are purpose-built for iOS passcode bypass, leading candidates to choose a familiar name like Cellebrite instead of the correct specialized tool.

How to eliminate wrong answers

Option A is wrong because Cellebrite UFED is a versatile forensic tool that supports both physical and logical extraction across many mobile platforms, but it is not specifically designed for iOS physical extraction and does not specialize in bypassing passcode restrictions on modern iPhones as GrayKey does. Option C is wrong because Magnet AXIOM is a comprehensive digital forensic platform for analyzing data from computers, mobile devices, and cloud sources, but it relies on third-party tools for physical extraction and does not directly perform hardware-level passcode bypass on iOS devices. Option D is wrong because Oxygen Forensic Detective is a mobile forensic tool that supports logical and file system extractions, but it lacks the specialized hardware and software capabilities for brute-forcing iOS passcodes on modern iPhones with Secure Enclave protection.

119
MCQmedium

An investigator examines an iPhone backup file. Inside the backup manifest, they find a file path 'AppDomainGroup-group.com.example.app'. This indicates the data belongs to which type of app container?

A.System container for iOS system apps
B.The app's sandbox container
C.A shared container for multiple apps from the same developer
D.Temporary container for app data
AnswerC

The 'AppDomainGroup-' prefix in an iOS backup identifies a shared container that is part of an app group, which allows multiple apps from the same developer to access common files and preferences. These groups are declared via the com.apple.security.application-groups entitlement, and the container is stored outside each app's individual sandbox. Therefore, when an investigator sees this prefix, it correctly means a shared container for multiple apps from the same developer.

Why this answer

The file path 'AppDomainGroup-group.com.example.app' indicates a shared container used by App Groups, a feature that allows multiple apps from the same developer to share data. This is not a sandbox container for a single app, nor is it a system or temporary container. The 'group' prefix and the bundle identifier pattern confirm it belongs to a shared app group container.

Exam trap

EC-Council often tests the distinction between 'AppDomain-' (single app sandbox) and 'AppDomainGroup-' (shared container), and candidates mistakenly pick the sandbox container option because they overlook the 'group' keyword in the path.

How to eliminate wrong answers

Option A is wrong because system containers for iOS system apps use paths like '/System/Library' or '/var/containers/Bundle/System', not 'AppDomainGroup-'. Option B is wrong because an app's sandbox container uses the 'AppDomain-' prefix (e.g., 'AppDomain-com.example.app'), not 'AppDomainGroup-'. Option D is wrong because temporary containers use paths like 'tmp/' or 'Caches/' within the app's sandbox, not a dedicated 'AppDomainGroup-' domain.

← PreviousPage 2 of 2 · 119 questions total

Ready to test yourself?

Try a timed practice session using only Mobile and Malware Forensics questions.