Mobile Device Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Mobile Device Forensics flashcards as text
A CHFI investigator examines a suspect's iPhone backup stored on a Windows PC. Where are iTunes backups located by default?
Answer: C:\Users\\AppData\Roaming\Apple Computer\MobileSync\Backup
iTunes stores iPhone backups in the AppData\Roaming\Apple Computer\MobileSync\Backup directory on Windows.
What is the significance of the 'Manifest.db' file found in an iOS iTunes backup?
Answer: Maps hashed backup file names to original file paths and metadata
Manifest.db is a SQLite database that maps the SHA1-hashed filenames in the backup to their original file paths and metadata.
Which mobile forensic artifact on Android contains a record of all installed packages, their permissions, and signing certificates?
Answer: /data/system/packages.xml
The packages.xml file in /data/system/ maintains a registry of all installed applications, their permissions, and signing certificates.
During a CHFI investigation, an examiner recovers WhatsApp messages from an Android device. Where is the WhatsApp message database typically stored?
Answer: /data/data/com.whatsapp/databases/msgstore.db
WhatsApp stores its message database at /data/data/com.whatsapp/databases/msgstore.db, which requires root access to read directly.
What does the term 'acquisition window' refer to in mobile device forensics?
Answer: The period between seizure and examination during which volatile data may be lost
The acquisition window is the critical period between device seizure and examination during which volatile evidence (RAM, cache) can degrade or be lost.
An investigator finds evidence of a deleted photo on an iPhone. Which iOS artifact might still contain thumbnail references to the deleted image?
Answer: Photos.sqlite
Photos.sqlite maintains the iOS photo library database, which may retain records and thumbnail references even after an image is deleted.
Which standard governs the handling of digital evidence in mobile forensics to ensure admissibility in US courts?
Answer: NIST SP 800-101
NIST Special Publication 800-101 'Guidelines on Mobile Device Forensics' provides the standard framework for mobile evidence handling in the US.