Courseiva

CHFI Mobile and Malware Forensics Practice Question

In iOS forensics, which database file typically contains the call history, including incoming, outgoing, and missed calls?

⚠ Common exam trap

EC-Council often tests the misconception that `AddressBook.db` or `SMS.db` might contain call logs because they store contact names and message threads, but the trap is that call history is stored in a separate, dedicated database (`call_history.db`) that is not linked to the address book or SMS databases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

call_history.db

In iOS forensics, the call history (incoming, outgoing, and missed calls) is stored in the SQLite database file named `call_history.db`. This database is located within the root domain of the iOS file system (typically under `/private/var/mobile/Library/CallHistoryDB/`) and contains tables such as `call` and `call_history` that record each call's direction, duration, timestamp, and associated contact identifier. The CHFI exam specifically tests this file as the authoritative source for call log evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notes.db

    Why it's wrong here

    Notes.db is a SQLite database backing the Apple Notes application, storing note content, rich text, attachments, and metadata such as creation and modification timestamps. It does not record system telephony events, so it has no call date, duration, or participant fields. While a note could contain pasted call details, it is not a system call log source.

  • ✓

    call_history.db

    Why this is correct

    call_history.db, typically under /private/var/mobile/Library/CallHistoryDB/, is the system SQLite database populated by the telephony daemon for all incoming, outgoing, and missed calls. It preserves fields such as the peer phone number, call date, duration, call status, and unique identifiers. In iOS forensics, this is the authoritative source for call records.

  • ✗

    AddressBook.db

    Why it's wrong here

    AddressBook.db is the contacts database, storing person records with names, phone numbers, email addresses, postal addresses, and relationship fields. It contains the numbers that may be linked to call entries, but it lacks the event-specific fields—timestamp, duration, direction—needed to answer a call history question. Therefore it cannot serve as the call log database.

  • ✗

    SMS.db

    Why it's wrong here

    SMS.db is the SQLite store for SMS, iMessage, and MMS conversations, containing message text, sender/receiver identifiers, attachments, and delivery timestamps. It handles chat threads, not telephony call metadata such as call duration or missed-call flags. Thus it is unrelated to the call record database requested in the question.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.