CHFI Mobile and Malware Forensics Practice Question
Which mobile forensics tool is specifically designed for physical extraction of iOS devices, including bypassing passcodes and extracting full file system images?
⚠ Common exam trap
Many candidates confuse Cellebrite UFED's broad device support with the specific ability to perform physical extraction and passcode bypass on iOS, but Cellebrite's iOS capabilities are more limited compared to GrayKey's specialized focus.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GrayKey
GrayKey is a specialized forensic tool developed by GrayShift that performs physical extraction on iOS devices, including bypassing passcodes and obtaining full file system images. It exploits hardware and software vulnerabilities in iOS to extract data, making it the correct choice for this specific task.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Oxygen Forensic Detective
Why it's wrong here
Oxygen Forensic Detective is a versatile multi-platform forensic suite that excels at logical and file-system acquisitions, cloud data extraction, and agent-based collection across mobile devices. However, it lacks a dedicated hardware mechanism for bypassing Apple's Secure Enclave or performing low-level physical memory dumps on iOS devices. Its iOS support is primarily logical/backup-oriented, so it is not the tool specifically designed for physical extraction.
- ✗
Magnet AXIOM
Why it's wrong here
Magnet AXIOM is a comprehensive forensic analysis and artifact-discovery platform that ingests evidence from many sources, including images created by other acquisition tools. It does not itself perform physical extraction from an iOS device; instead, it relies on external tools to acquire a forensic image before analysis. Because AXIOM is an investigation and reporting suite rather than a specialized hardware/software extraction system, it cannot directly bypass an iPhone passcode or access the Secure Enclave.
- ✗
Cellebrite UFED
Why it's wrong here
Cellebrite UFED is a widely deployed forensic extraction tool that supports both Android and iOS logical, file-system, and in some cases physical extractions. Although UFED has advanced capabilities for many devices, modern iPhones with strong encryption and Secure Enclave protection present significant challenges that UFED cannot always overcome, especially when a passcode is set. GrayKey, by contrast, is a purpose-built iOS-only device optimized for physical extraction and passcode bypass, making UFED less specialized for this specific task.
- ✓
GrayKey
Why this is correct
GrayKey, developed by Grayshift, is a dedicated iOS forensic tool engineered specifically for physical extraction and passcode bypass. It exploits hardware and software vulnerabilities to gain full file-system access from locked iPhones/iPads, bypassing the Secure Enclave's retry limits. Law enforcement agencies use GrayKey for targeted deep extraction of iOS devices, making it the only option in this list uniquely designed for this purpose.
Go deeper
Related to this question
About these practice questions
One of 205 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.