โ† All ACI Flashcard Decks

Mobile Device Forensics Flashcards

7 cards from real ACI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Mobile Device Forensics flashcards as text
  1. What is the forensic significance of a 'deleted' flag in a SQLite database found on a mobile device?

    Answer: The record is marked for deletion but the data may still be fully recoverable

    SQLite uses lazy deletion, meaning deleted records are flagged but remain in the database pages until the space is reallocated, allowing forensic tools to recover complete deleted records.

  2. Which type of records can investigators subpoena from cellular carriers to establish a mobile device's historical location and communication activity?

    Answer: Call Detail Records (CDRs) from cellular carriers

    Call Detail Records (CDRs) maintained by GSM and CDMA cellular carriers log call times, durations, and cell tower connections, providing location and communication data obtainable via legal subpoena.

  3. What types of investigative data can EXIF metadata embedded in mobile device photographs provide?

    Answer: GPS coordinates, device model, manufacturer, and timestamp

    EXIF metadata embedded in photos can reveal GPS coordinates where the photo was taken, the device model and manufacturer, exact timestamp, and camera settings, providing valuable investigative intelligence.

  4. Which mode on Qualcomm-based Android devices can be exploited to bypass device security and perform direct memory extraction?

    Answer: EDL (Emergency Download) mode

    Emergency Download (EDL) mode is a Qualcomm diagnostic bootloader mode that, when exploited with appropriate tools, allows direct flash memory access and data extraction bypassing Android security.

  5. Which file on an Android device contains a comprehensive registry of all installed applications including system and user-installed apps?

    Answer: /data/system/packages.xml

    The packages.xml file located at /data/system/ on Android devices maintains a complete record of all installed applications, their permissions, version information, and installation paths.

  6. In a corporate forensic investigation, what forensic value can Mobile Device Management (MDM) system records provide?

    Answer: They contain device activity logs, app install records, and policy compliance history

    MDM systems maintain logs of device activity, remote commands issued, application installations, and policy compliance events, providing investigators with an independent record of corporate device usage.

  7. When a mobile device is found powered off at a crime scene, what is the recommended forensic approach?

    Answer: Keep the device powered off, document its state, and transport it in a Faraday bag

    A powered-off device should remain off to avoid data changes during boot, and its state should be documented before acquisition, with Faraday shielding used during transport to prevent wireless access.