Mobile Device Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Mobile Device Forensics flashcards as text
What is the primary forensic challenge posed by Apple's 'Secure Enclave Processor' (SEP) in modern iPhones?
Answer: It stores encryption keys that cannot be extracted even by Apple
The SEP stores cryptographic keys in hardware that are never exposed to the main OS, making brute-force attacks the only viable method.
A forensic examiner is analyzing an Android device and finds the file '/data/system/gesture.key'. What does this file contain?
Answer: A SHA1 hash of the screen unlock pattern
gesture.key contains an unsalted SHA1 hash of the Android unlock pattern, which can potentially be cracked offline.
Which mobile forensic technique involves using specialized hardware clips to read flash memory without desoldering the chip?
Answer: ISP (In-System Programming)
ISP (In-System Programming) uses test pads on the PCB to read flash memory directly without removing the chip.
During iOS forensic analysis, what is the forensic significance of the 'KnowledgeC.db' database?
Answer: Records app usage, device wake/sleep events, and location data with timestamps
KnowledgeC.db is an iOS Core Data store that tracks app usage patterns, device states, and user activities with precise timestamps.
What does 'GrayKey' primarily enable in mobile forensics investigations?
Answer: Physical extraction and passcode bypass on iPhones
GrayKey is a law enforcement tool developed by Grayshift that enables passcode brute-forcing and physical data extraction from iPhones.
An examiner recovers a mobile device from a crime scene still powered on. According to best practices, what should be done first?
Answer: Place it in a Faraday bag to isolate it from networks while keeping it powered
Keeping the device powered on in a Faraday bag preserves volatile data while preventing remote wipe commands from reaching it.
Which artifact on Android devices records the history of Wi-Fi networks the device has connected to, including SSID and BSSID information?
Answer: /data/misc/wifi/WifiConfigStore.xml
WifiConfigStore.xml (on newer Android versions) stores saved Wi-Fi network profiles including SSID, BSSID, and authentication details.