CDFI Mobile Device & Cloud Forensics Flashcards
6 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CDFI Mobile Device & Cloud Forensics flashcards as text
In cloud forensics, what does 'data sovereignty' mean and why is it forensically significant?
Answer: The legal jurisdiction governing data based on where it is physically stored
Data sovereignty means the laws of the country where data physically resides apply to it, which affects what legal process US investigators must follow to access data stored abroad.
Which artifact on an Android device stores SMS and MMS messages that a forensic investigator should examine?
Answer: mmssms.db
The mmssms.db SQLite database on Android devices stores all SMS and MMS messages, making it a primary target for communication evidence in mobile forensics.
What is the significance of 'EXIF metadata' embedded in photos from a mobile device in a forensic investigation?
Answer: It contains GPS coordinates, timestamps, and device information that corroborate or contradict a suspect's alibi
EXIF metadata in photos records GPS location, date/time, camera model, and settings, providing investigators with powerful corroborating or contradicting evidence for a suspect's location and timeline.
Which cloud storage service log would be MOST useful for determining when a suspect uploaded files to a shared drive?
Answer: Cloud provider audit/access logs (e.g., AWS CloudTrail, Google Workspace audit logs)
Cloud provider audit logs record specific API calls, file uploads, access events, and user actions with timestamps, directly evidencing when and what a user uploaded.
During mobile forensics, what is 'app data sandboxing' and how does it affect evidence collection?
Answer: iOS/Android isolation of each app's data in its own directory, limiting cross-app access and requiring elevated privileges to extract
App sandboxing restricts each app's data to its own protected directory; forensic investigators typically need a jailbreak/root or physical extraction to access sandboxed app data from competing apps.
What is the primary forensic challenge with end-to-end encrypted messaging apps like Signal on a mobile device?
Answer: Messages are only decryptable on the endpoint device; cloud servers hold no readable content
End-to-end encryption ensures only the communicating devices hold decryption keys, so investigators must acquire the physical device to access message content—server-side requests yield only encrypted ciphertext.