Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilComputer Hacking Forensic Investigator

Domain 7Objective 1

Mobile Forensics CHFI Practice Questions (Page 5)

Part of the Mobile and IoT Forensics domain, which makes up ~14% of our current practice bank.

49questions here
10free pages
13concepts

Questions 21–25

  1. 21foundation · easy

    What is the purpose of maintaining a chain of custody for mobile evidence?

    Select an answer first
  2. 22application · medium

    During analysis of an iOS device backup, an examiner needs to locate the SQLite database that contains the user's text message history. Which file path within the backup should the examiner examine?

    Select an answer first
  3. 23application · medium

    A small business is investigating a potential data leak from a company-issued smartphone. The phone is used by an employee and contains both personal and corporate data. The business wants to preserve evidence while respecting privacy. Which approach is most appropriate?

    Select an answer first
  4. 24expert · hard

    An analyst is examining a mobile device that is suspected of being infected with malware. The malware appears to be sending SMS messages to a premium-rate number. Which forensic artifact would provide the most direct evidence of this behavior?

    Select an answer first
  5. 25expert · hard

    A forensic examiner is analyzing an Android device and needs to recover deleted text messages. The device uses full-disk encryption and is rooted. Which acquisition method is most likely to recover the deleted messages?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.