Courseiva

CHFI Mobile and Malware Forensics Practice Question

During an iOS forensic examination, an analyst extracts the SMS.db file from an iTunes backup. Which table within this database contains the actual message content and associated metadata such as timestamps and sender/recipient information?

⚠ Common exam trap

EC-Council often tests the distinction between the `message` table (content + timestamps) and the `handle` table (contact identifiers), leading candidates to confuse the `handle` table as containing message data when it only stores address book references.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

message

The `message` table in SMS.db stores the actual message content (the `text` field) along with critical metadata such as `date` (Unix timestamp), `is_from_me` (sender/recipient indicator), and `handle_id` (foreign key to the `handle` table). This is the primary table for message body and timestamp data in iOS SMS/MMS forensics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    chat

    Why it's wrong here

    The 'chat' table in iOS's sms.db stores session-level metadata, including chat identifier, display name, service type (iMessage/SMS), and timestamps for thread activity. It does not contain the actual text payloads; individual messages are recorded in the 'message' table. Therefore, selecting from 'chat' alone would reveal thread structure but never the analyst's sought message content.

  • ✓

    message

    Why this is correct

    The 'message' table is the core target because each row represents a single SMS or iMessage, with columns such as 'text' (the message body), 'date' (absolute Unix time), 'is_from_me', and 'handle_id' linking to the sender. Logical forensic extraction typically includes this table to recover the actual words exchanged. Even when attachments or group metadata are involved, the text originates here, making it the correct choice.

  • ✗

    attachment

    Why it's wrong here

    The 'attachment' table stores metadata about file transfers, such as filename, content type, transfer state, and a file path on disk, but never the textual content of a chat message. It links to messages through the 'message_attachment_join' table, and any readable body text remains in the 'message' table. An analyst extracting only attachments would get files, not the message conversation.

  • ✗

    handle

    Why it's wrong here

    The 'handle' table acts as an address book index for remote parties, storing phone numbers, email addresses, and a service identifier (e.g., iMessage or SMS). Message rows reference handles via 'handle_id' to attribute authorship, but the table contains no message text or body fields. Its purpose is entity resolution, not content storage, so it cannot satisfy a request for the actual message content.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.