Courseiva

CHFI Mobile and Malware Forensics Practice Question

During an iOS forensics investigation, an examiner wants to extract call history records from an iPhone backup. Which SQLite database file should be examined?

⚠ Common exam trap

EC-Council often tests the specific naming of iOS forensic artifacts; the trap here is that candidates confuse 'SMS.db' (which stores messages) with call logs, or assume call history is stored in a more generic database like 'AddressBook.db'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

call_history.db

In iOS forensics, call history records are stored in the SQLite database file named 'call_history.db' (or 'CallHistory.storedata' in newer iOS versions). This database contains tables such as 'call' and 'ZCALLRECORD' that log incoming, outgoing, and missed calls along with timestamps and durations. Examining this file directly from an iTunes backup or device extraction provides the examiner with the complete call log.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SMS.db

    Why it's wrong here

    SMS.db is the SQLite database located at /private/var/mobile/Library/SMS/sms.db. It stores SMS and iMessage conversations, including message bodies, senders, receivers, timestamps, and attachments. Call records, such as duration, call direction, and SIM information, are never written to this database; they reside in a dedicated call history database instead. Therefore, while SMS.db is rich in messaging artifacts, it is not the correct source for call history.

  • ✗

    AddressBook.db

    Why it's wrong here

    AddressBook.db (or ContactsDB) holds contact records: first/last name, phone numbers, email addresses, and postal addresses. It is a relational directory linked to communication apps, but it does not contain call history entries like call timestamps, durations, or missed-call flags. Forensic examiners may use it to correlate a phone number with a contact, not to recover the call log itself. Thus, this database is irrelevant when the explicit goal is extracting call history.

  • ✓

    call_history.db

    Why this is correct

    call_history.db is the correct source for call records on iOS devices. This SQLite database, commonly found under /private/var/mobile/Library/CallHistoryDB/, stores recent calls with fields such as the caller/called number, timestamp, duration, and call status (incoming, outgoing, missed). The database is periodically flushed or pruned, but deleted records may remain in free pages or the WAL file until overwritten. Its schema directly answers the examiner's question about call history.

  • ✗

    Calendar.sqlitedb

    Why it's wrong here

    Calendar.sqlitedb is the SQLite database for calendar data, including events, reminders, attendees, and alarms. It is managed by the EventKit framework and stores dates and notes, but it contains no call metadata such as numeric caller IDs or call durations. Its presence is useful for building a timeline of a user's activities, but it cannot answer a question about call history. Therefore, this file is an incorrect target for a call-history investigation.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.