Courseiva
Mobile and Malware ForensicseasyMultiple ChoiceObjective-mapped

CHFI Mobile and Malware Forensics Practice Question

Which mobile forensic tool is commonly used to perform a physical extraction of an iOS device, including bypassing the lock screen on certain models?

⚠ Common exam trap

EC-Council often tests the distinction between logical extraction tools (like Magnet AXIOM or Oxygen Forensic Detective) and hardware-based physical extraction tools (like GrayKey), leading candidates to mistakenly choose a familiar forensic suite that cannot bypass iOS lock screens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

GrayKey

GrayKey is a specialized hardware tool designed by Grayshift that performs physical extraction of iOS devices, including bypassing the lock screen on certain models (e.g., iPhone 5 through iPhone X) by exploiting bootrom vulnerabilities or using brute-force techniques. It is widely used in law enforcement for forensic acquisition of iOS devices where logical extraction is insufficient.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Magnet AXIOM

    Why it's wrong here

    Magnet AXIOM is a forensic evidence processing and analysis platform that ingests artifacts from many sources—including smart device acquisitions, cloud data, and computer images—but it is not an acquisition tool capable of performing a physical extraction on a locked iOS phone. To obtain a physical image, an examiner must first use a dedicated low-level tool such as GrayKey or Cellebrite UFED, after which AXIOM can parse and analyze the resulting image. AXIOM's role is analysis and artifact correlation, not the hardware-level passcode bypass or flash memory imaging required for physical extraction.

  • GrayKey

    Why this is correct

    GrayKey is a hardware-software system developed by Grayshift specifically for law enforcement and forensic use, designed to perform passcode bypass and physical extraction from iOS devices. It exploits bootrom or Secure Enclave vulnerabilities to derive the passcode and decrypt the file system, yielding a full filesystem image, keychain, and app data even from locked devices. This capability makes it the de facto standard for iOS physical extraction in many criminal investigations, distinguishing it from general-purpose mobile forensic platforms.

  • Oxygen Forensic Detective

    Why it's wrong here

    Oxygen Forensic Detective is a mobile forensic suite that supports logical, filesystem, and cloud extraction from iOS and Android devices, but it does not advertise or implement the same dedicated passcode bypass mechanisms as GrayKey. On locked modern iPhones, Oxygen typically requires the device to be already unlocked or relies on prior jailbreaks or forensic cloud access, rather than performing a hardware-level physical acquisition. It can analyze GrayKey output, but it is not the tool commonly associated with physically extracting data from a locked iOS device.

  • FTK Imager

    Why it's wrong here

    FTK Imager is a traditional computer forensic tool for creating bit-identical disk images of hard drives, solid-state drives, and removable media, and for imaging volatile memory in limited cases. It has no native interface to connect to a mobile device's Apple Mobile Device protocol nor the hardware capabilities to interact with an iPhone's Secure Enclave or NAND flash. Consequently, it cannot perform a physical extraction on iOS; it remains a disk and computer imaging utility, not a mobile acquisition solution.

About these practice questions

One of 205 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.