CHFI Mobile and Malware Forensics Practice Question
Which TWO of the following are primary purposes of using the GrayKey tool in iOS forensics?
⚠ Common exam trap
EC-Council often tests the distinction between 'bypassing the passcode' (option D) and 'extracting the file system' (option C) as separate but complementary purposes, leading candidates to incorrectly select only one when both are primary functions of GrayKey.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Extract the full file system from a locked iOS device
Option C is correct because GrayKey is a hardware-based forensic tool designed to perform full file system extractions from iOS devices, including locked ones, providing investigators with a complete image of the device's data rather than just a logical backup. Option D is correct because a core function of GrayKey is passcode bypass — it uses brute-force and exploit techniques to defeat the iOS lock screen passcode, which is the prerequisite that enables the full file system extraction in option C. Options A and B are incorrect because GrayKey is not a static malware analysis platform nor a binary decryption tool; those tasks are handled by disassemblers and reverse-engineering suites such as IDA Pro, Ghidra, or Hopper. Option E is incorrect because GrayKey does not create encrypted iTunes backups — that is the function of iTunes/Finder or libimobiledevice, and GrayKey's purpose is direct device extraction, not backup generation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform static analysis of iOS malware
Why it's wrong here
GrayKey is a forensic acquisition appliance from Grayshift that is engineered to remove or bypass an iOS device's lock screen for data extraction, not to analyze malicious software. Static analysis of iOS malware requires disassembling Mach-O binaries, inspecting assembly instructions, and tracing API calls in a controlled sandbox, which GrayKey does not perform. Its hardware and firmware focus on imaging the device's storage, so it cannot recognize, unpack, or classify malware.
- ✗
Decrypt iOS application binaries for analysis
Why it's wrong here
GrayKey extracts the device's file system and keychain, but it does not strip FairPlay DRM from App Store binaries. Decrypting iOS application binaries for static analysis normally requires runtime key extraction via tools like frida-ios-dump, Clutch, or bagbak on a jailbroken or specially provisioned device. GrayKey's output is a raw forensic image, not decrypted application payloads, so this task falls outside its acquisition role.
- ✓
Extract the full file system from a locked iOS device
Why this is correct
Once GrayKey successfully bypasses or brute-forces a lock screen passcode, one of its primary forensic functions is creating a full file system extraction from the iOS device's internal storage. This extraction preserves the user data partition, application sandboxes, and system files in a forensically sound manner for later analysis. Unlike logical backups, this captures deleted files and unallocated data, making it a core reason investigators deploy GrayKey.
- ✓
Bypass the iOS passcode to gain access to the device
Why this is correct
GrayKey is specifically designed to bypass iOS passcodes by exploiting bootrom or bootloader vulnerabilities (e.g., checkm8) to disable the device's brute-force attempt limits and perform offline passcode guessing. This grants lawful forensic access to the device's encrypted data without user credentials, which is a central purpose of the tool. The bypass enables subsequent extractions, but the passcode recovery itself is the essential first step that distinguishes GrayKey from ordinary forensic software.
- ✗
Create an encrypted iTunes backup
Why it's wrong here
Encrypted iTunes backups are generated by Apple's iTunes/Finder software or third-party libraries like libimobiledevice, using a user-supplied backup password to encrypt archive data. GrayKey is a hardware forensic acquisition tool that connects to Lightning ports and directly images device storage; it does not invoke backup routines or create backup archives. Confusing the two conflates an acquisition method with a backup artifact, and backup creation is not a function of GrayKey.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.