CHFI Mobile and Malware Forensics Practice Question
During a mobile forensic investigation, an examiner finds that the seized iPhone is locked with a passcode but is running iOS 11. Which acquisition method should the examiner prioritize to obtain the most data without bypassing the passcode?
⚠ Common exam trap
The CHFI exam often tests the misconception that physical acquisition is always superior, but on modern iOS devices, logical acquisition via iTunes backup is the only viable method for locked devices without bypassing the passcode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Logical acquisition via iTunes backup
For a locked iPhone running iOS 11, physical and file system acquisitions are typically blocked by hardware encryption and the Secure Enclave unless the passcode is bypassed. However, if the device has been previously trusted with a computer, a logical acquisition via iTunes backup can be performed without entering the passcode, as the trust relationship authorizes the backup. This method extracts the most data (contacts, messages, photos, etc.) without bypassing the passcode. If no trust relationship exists, logical acquisition is not possible without the passcode, but the CHFI exam often assumes a previously trusted computer for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical acquisition using a JTAG tool
Why it's wrong here
Physical acquisition requires passcode bypass or advanced techniques like JTAG, which may not be feasible on iOS 11 without device-specific tools.
- ✓
Logical acquisition via iTunes backup
Why this is correct
iTunes backup can be initiated without passcode if device is trusted, and provides access to many artefacts including SMS, contacts, and call history.
- ✗
File system acquisition using Cellebrite UFED
Why it's wrong here
File system acquisition on iOS 11 typically requires passcode bypass or jailbreak; not possible without it.
- ✗
Manual acquisition by photographing the screen
Why it's wrong here
Manual acquisition yields only visible data and is not prioritized when more comprehensive methods are available.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Forensic Investigation Process
The forensic investigation process is a structured series of steps used to collect, preserve, analyze, and present digital evidence from computers and networks for legal or internal purposes.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.