โ† All CHFI Flashcard Decks

Mobile Device Forensics Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Mobile Device Forensics flashcards as text
  1. What is the primary purpose of a Faraday bag in mobile device forensics?

    Answer: Block electromagnetic signals to prevent remote wipe

    A Faraday bag shields the device from cellular, Wi-Fi, and Bluetooth signals, preventing remote wipe commands from reaching it.

  2. Which Apple forensic artifact records the last known location of an iOS device along with timestamps and accuracy radius?

    Answer: routined database

    The routined daemon manages significant location tracking on iOS, storing data in its associated database files.

  3. An investigator needs to bypass Android's FRP (Factory Reset Protection) lock during forensic examination. What is the primary challenge FRP presents?

    Answer: Requires original Google account credentials to activate after reset

    FRP requires the original Google account credentials to be entered after a factory reset, preventing unauthorized activation of the device.

  4. Which iOS file system partition contains the user's data, installed apps, and forensically relevant artifacts?

    Answer: /private/var

    The /private/var partition (user data partition) on iOS contains all user-generated data, app data, and forensic artifacts.

  5. What Android debug feature, when enabled, allows forensic tools to communicate with a device via USB for data extraction?

    Answer: ADB (Android Debug Bridge)

    ADB (Android Debug Bridge) is a command-line tool that enables communication between a computer and an Android device for extraction and analysis.

  6. During iOS forensic analysis, the examiner finds a 'Snapshots' folder inside an app's container. What does this typically contain?

    Answer: Screenshots taken by iOS for the app switcher

    iOS captures screenshots of app content when the user presses the Home button; these snapshots are stored for the app switcher display.

  7. Which protocol allows forensic examiners to extract data from older iPhones by exploiting vulnerabilities in the DFU mode?

    Answer: checkm8 bootrom exploit

    The checkm8 bootrom exploit targets an unpatchable vulnerability in Apple's A5-A11 chips, enabling DFU-mode extraction of encrypted data.