Courseiva

CHFI Mobile and Malware Forensics Practice Question

During a forensic investigation of an Android device, the examiner uses ADB to extract data. Which command would create a full backup of the device's data partition, including app data and shared storage?

⚠ Common exam trap

The CHFI exam often tests the distinction between backup creation (`adb backup`) and restoration (`adb restore`), or between logical backups (ADB backup) and physical imaging (`dd`), leading candidates to confuse the purpose of each command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

adb backup -f backup.ab -apk -shared -all

The `adb backup -f backup.ab -apk -shared -all` command creates a full Android backup that includes all apps and their data (via `-all`), includes APK files (via `-apk`), and includes shared storage (via `-shared`), outputting a single `.ab` file. This is the standard ADB method for non-rooted devices to capture a comprehensive logical backup of app data and shared storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    adb backup -f backup.ab -apk -shared -all

    Why this is correct

    The `adb backup -f backup.ab -apk -shared -all` command invokes Android's Backup Manager over ADB to create a non-root full logical backup, writing an Android Backup (AB) archive that contains installed APKs (-apk), shared/sdcard data (-shared), and all application data (-all). In forensic triage, this is the correct method to capture user-visible app data without altering the device's system partition, although it cannot retrieve protected app-private files from apps that disable backup or obtain deleted data. The resulting backup.ab can later be parsed with tools like Android Backup Extractor (abe) to reconstruct app content for analysis.

  • ✗

    adb shell dd if=/dev/block/mmcblk0 of=/data/backup.img

    Why it's wrong here

    The command `adb shell dd if=/dev/block/mmcblk0 of=/data/backup.img` is a physical acquisition technique that copies the raw eMMC block device bit-for-bit, but it is unavailable on production Android devices without root access because the shell user lacks read permission to the block node and SELinux blocks it. Even if executed with root, writing the image to `/data/backup.img` on the same device contaminates the evidence: the write itself modifies the filesystem, can overwrite free-space/deleted data, and leaves a copy on the suspect medium rather than a forensically sound external storage. It is not a standard ADB backup command and is only appropriate for a targeted chip-off or rooted physical dump with output redirected to an examiner-controlled workstation via `adb shell` and `dd` piped to a local file.

  • ✗

    adb pull /data/data/

    Why it's wrong here

    The command `adb pull /data/data/` attempts to recursively copy the application-private data directory from the device to the workstation, but on a non-rooted forensic device, the adbd daemon runs as the `shell` user, which cannot traverse `/data/data` due to Unix permissions and SELinux restrictions; this results in permission denied errors or incomplete pulls of world-readable subdirectories only. If the device were rooted, the pull would still lack the structured Android Backup container, would not include APKs or shared storage, and the live file copy would not provide a coherent snapshot, as app files can change while being read, risking hash mismatches and missing SQLite WAL/SHM sidecars. Thus, `adb pull` is a file-explorer-level retrieval tool, not an ADB backup operation.

  • ✗

    adb restore backup.ab

    Why it's wrong here

    The command `adb restore backup.ab` is the inverse of acquisition: it pushes data from a backup archive onto the device, overwriting existing applications and their data. Running this on a suspect device during an investigation destroys current evidence by replacing it with archived content, and it also alters the device's backup-token state, forcing data-breach indicators. Because the question asks for a command that creates a backup, `restore` is fundamentally wrong; it consumes a `.ab` file rather than producing one.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.