nerdexam
EC-Council

312-49V11 · Question #55

During a digital forensic investigation into a suspect's Android device, a forensic expert is tasked with extracting Chrome artifacts such as browsing history, cookies, and cached data. The suspect…

The correct answer is D. Magnet AXIOM. Under the CHFI v11 Mobile and IoT Forensics domain, investigators are required to extract and analyze application-level artifacts from mobile devices to reconstruct user activity. Web browsers such as Google Chrome store valuable forensic data on Android devices, including…

Mobile Forensics

Question

During a digital forensic investigation into a suspect's Android device, a forensic expert is tasked with extracting Chrome artifacts such as browsing history, cookies, and cached data. The suspect may have used Chrome for browsing activities related to a cybercrime, and the investigator needs a tool that can efficiently extract this type of information from the device. Which of the following tools can assist the investigator in extracting these Chrome artifacts from an Android device?

Options

  • ALOIC
  • BOrbot Proxy
  • CDroidSheep
  • DMagnet AXIOM

How the community answered

(66 responses)
  • A
    5% (3)
  • B
    9% (6)
  • C
    2% (1)
  • D
    85% (56)

Explanation

Under the CHFI v11 Mobile and IoT Forensics domain, investigators are required to extract and analyze application-level artifacts from mobile devices to reconstruct user activity. Web browsers such as Google Chrome store valuable forensic data on Android devices, including browsing history, cookies, cached files, saved form data, session tokens, and timestamps, which can be critical in cybercrime investigations. Magnet AXIOM is a comprehensive digital forensics platform explicitly supported and referenced in CHFI v11 for mobile device forensic analysis. It is capable of performing logical and file system extractions from Android devices and includes built-in parsers for Chrome artifacts. Magnet AXIOM can automatically locate Chrome databases (such as History, Cookies, and cache directories), decode SQLite databases, and present the extracted data in a forensically structured and timeline-based view. This makes it highly effective for correlating browser activity with other

Topics

#mobile forensics#Android forensics#Chrome artifacts#Magnet AXIOM

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice