
EC-CouncilComputer Hacking Forensic Investigator
Domain 7Objective 1
Mobile Forensics CHFI Practice Questions (Page 5)
Part of the Mobile and IoT Forensics domain, which makes up ~14% of our current practice bank.
49questions here
10free pages
13concepts
Questions 21–25
- 21
What is the purpose of maintaining a chain of custody for mobile evidence?
Select an answer first - 22
During analysis of an iOS device backup, an examiner needs to locate the SQLite database that contains the user's text message history. Which file path within the backup should the examiner examine?
Select an answer first - 23
A small business is investigating a potential data leak from a company-issued smartphone. The phone is used by an employee and contains both personal and corporate data. The business wants to preserve evidence while respecting privacy. Which approach is most appropriate?
Select an answer first - 24
An analyst is examining a mobile device that is suspected of being infected with malware. The malware appears to be sending SMS messages to a premium-rate number. Which forensic artifact would provide the most direct evidence of this behavior?
Select an answer first - 25
A forensic examiner is analyzing an Android device and needs to recover deleted text messages. The device uses full-disk encryption and is rooted. Which acquisition method is most likely to recover the deleted messages?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.