← All ACI Flashcard Decks

Mobile Device Forensics Flashcards

7 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Mobile Device Forensics flashcards as text
  1. What is the first step when handling a mobile device at a crime scene to preserve evidence integrity?

    Answer: Place the device in a Faraday bag to prevent wireless network connectivity

    Placing the device in a Faraday bag blocks all wireless signals (cellular, Wi-Fi, Bluetooth) and prevents remote wipe commands or data modification before acquisition.

  2. Which type of mobile device acquisition extracts raw binary data directly from the device's flash memory, including deleted files and unallocated space?

    Answer: Physical acquisition

    Physical acquisition performs a bit-for-bit image of the device's entire storage, capturing deleted data, unallocated space, and slack space for the most complete evidence.

  3. What does JTAG stand for in the context of mobile device forensics?

    Answer: Joint Test Action Group

    JTAG (Joint Test Action Group) is an industry standard originally designed for circuit board testing, used in forensics to access device memory through hardware test access ports.

  4. Which file system is primarily used by Apple iOS devices since iOS 10.3 for storing user data?

    Answer: APFS

    Apple File System (APFS) replaced HFS+ as the primary iOS file system starting with iOS 10.3, offering improved encryption, cloning, and space sharing capabilities.

  5. What is the primary forensic purpose of using a Faraday bag during mobile device evidence collection?

    Answer: To isolate the device from all wireless signals

    A Faraday bag provides electromagnetic shielding that blocks all wireless signals including cellular, Wi-Fi, Bluetooth, and GPS, preventing remote wipe commands from reaching the device.

  6. Which acquisition method for Android devices uses a developer tool built into the Android SDK and requires USB debugging to be enabled?

    Answer: ADB (Android Debug Bridge) acquisition

    ADB (Android Debug Bridge) is an Android SDK developer tool that enables logical acquisition of Android device data when USB debugging is enabled on the target device.

  7. Which AccessData tool is specifically designed for mobile device data parsing and analysis, including iOS iTunes backups?

    Answer: FTK Mobile Phone Examiner Plus (MPE+)

    FTK Mobile Phone Examiner Plus (MPE+) is AccessData's dedicated mobile forensics tool designed to acquire and analyze data from iOS and Android devices, including iTunes backups.