CDFI Mobile Device & Cloud Forensics Flashcards
6 cards from real CDFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CDFI Mobile Device & Cloud Forensics flashcards as text
Which technique is used to recover deleted files from a mobile device's flash memory during a CDFI investigation?
Answer: File carving from unallocated flash memory space
File carving scans raw flash memory for file header and footer signatures to reconstruct deleted files that no longer appear in the file system's directory structure.
In cloud forensics, what is a 'legal hold' and why is it critical to issue one quickly?
Answer: A formal notification to a cloud provider to preserve data and suspend normal deletion processes
A legal hold instructs the cloud provider to suspend routine data deletion and preserve relevant evidence; delayed issuance risks evidence being permanently destroyed by automatic retention policies.
What does analyzing a mobile device's 'location history' (e.g., from Google Maps or iOS Significant Locations) provide in a forensic investigation?
Answer: A timeline of physical locations visited by the device and its user
Location history logs store timestamped GPS coordinates of places the device visited, enabling investigators to build a precise physical movement timeline for a suspect.
When forensically examining a SIM card from a mobile device, which type of data can be extracted?
Answer: International Mobile Subscriber Identity (IMSI), stored contacts, and limited SMS records
A SIM card stores the IMSI (subscriber identity), carrier information, some contacts, and a limited number of SMS messages independent of the device's internal storage.
Which US federal law is most relevant when a CDFI investigator seeks to compel a domestic cloud provider to disclose stored electronic communications?
Answer: Stored Communications Act (SCA), 18 U.S.C. § 2701
The Stored Communications Act (SCA) governs law enforcement access to stored electronic communications held by third-party providers, defining required legal process for each data type.
What forensic artifact would BEST help an investigator determine which Wi-Fi networks a mobile device has previously connected to?
Answer: The device's saved/preferred Wi-Fi network list stored in configuration files
Mobile devices maintain a list of previously connected Wi-Fi networks (SSIDs and credentials) in configuration files, which can place the device at specific physical locations associated with those networks.