Mobile Device Forensics Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Mobile Device Forensics flashcards as text
What is the primary first step a forensic examiner should take when acquiring a mobile device as evidence?
Answer: Document and photograph the device in its current state
Documenting and photographing the device in its current state establishes the chain of custody and preserves the initial evidence condition before any acquisition steps.
Which mobile device extraction method provides the most comprehensive forensic data, including deleted files and unallocated space?
Answer: Physical extraction
Physical extraction creates a bit-by-bit copy of the entire device storage, including deleted data and unallocated space, making it the most comprehensive method.
What does JTAG stand for in the context of mobile device forensics?
Answer: Joint Test Action Group
JTAG stands for Joint Test Action Group, an industry standard hardware interface originally for circuit testing that forensic examiners use to access device memory directly through test ports.
Which file system format is predominantly used by Apple iOS devices since iOS 10.3?
Answer: APFS (Apple File System)
Apple File System (APFS) replaced HFS+ starting with iOS 10.3 and is optimized for flash storage, making it the primary file system examiners encounter on modern iOS devices.
What is the primary forensic reason for placing a mobile device in Airplane Mode during evidence acquisition?
Answer: To prevent remote wiping or unauthorized data modification
Airplane Mode disables all wireless communications, preventing remote wipe commands or data synchronization that could alter or destroy evidence on the device.
In mobile forensics, what is the term for physically removing and reading the memory chip directly from the circuit board?
Answer: Chip-off extraction
Chip-off extraction involves physically desoldering the memory chip from the device's PCB and reading it with specialized equipment, providing raw access to all stored data.
What is the default encryption state of Apple iOS devices running iOS 8 and later?
Answer: Encrypted by default using the user's passcode
Since iOS 8, Apple devices are encrypted by default using the user's passcode as part of the encryption key derivation, making data cryptographically inaccessible without the correct passcode.