Filters
Question type

Study Flashcards

Which of the following are methods for preserving mobile devices by isolating them from the networks?


A) Reconfigure the device to prevent communication from the network.
B) Place the device in an RF-shielded pouch.
C) Jam RF signaling in the immediate area.
D) All of the above.

E) A) and D)
F) None of the above

Correct Answer

verifed

verified

Mobile devices are considered to be a type of embedded system.

A) True
B) False

Correct Answer

verifed

verified

Something forensic examiners need to keep in mind when trying to brute force an SIM card that has had a PIN set is that the card will lock after the second failed attempt.

A) True
B) False

Correct Answer

verifed

verified

One of the dangers (from a forensic standpoint) of mobile devices is:


A) Connected networks can contain investigatively useful information.
B) Network service providers may provide information for comparison with data extracted from a mobile device.
C) Connected networks can enable offenders to delete data remotely.
D) Network service providers may provide additional historical call records.

E) All of the above
F) C) and D)

Correct Answer

verifed

verified

One major advantage of mobile devices from a forensic perspective is that:


A) People very seldom delete information from mobile devices.
B) The process for deleting information is much more complicated than for adding information, and users frequently don't delete things correctly.
C) Flash memory is deleted block-by-block and mobile devices generally wait for a block to be full before it is deleted.
D) Manufacturers reserve a part of memory for storing deleted items.

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

Although mobile devices may connect to networks, WiFi and Bluetooth connections, and desktops synchronizing software, the forensic examiner should focus entirely on the mobile device itself.

A) True
B) False

Correct Answer

verifed

verified

Forensic examiners should be aware that a mobile device with a blank or broken display:


A) May as well be thrown away, as no data will be recovered from it
B) May only indicate that the screen is damaged and it may still be possible to extract data
C) May require that the mobile device be sent out to the manufacturer for repairs
D) None of the above

E) A) and C)
F) B) and D)

Correct Answer

verifed

verified

B

One drawback of mobile device examination is that when a user deletes data on a mobile device that data is never recoverable.

A) True
B) False

Correct Answer

verifed

verified

The primary reason that brute-force methods are not used when trying to access an SIM card with the PIN set is:


A) A four-digit PIN represents 10,000 possible combinations.
B) After three failed attempts, the SIM card will become locked.
C) PIN disclosure by the offender can be required by a court order.
D) None of the above.

E) B) and D)
F) A) and D)

Correct Answer

verifed

verified

When analyzing a GPS-enabled mobile device, it is often possible to recover location information, import it into mapping software, and display the locations on a map.

A) True
B) False

Correct Answer

verifed

verified

Why is it important to collect charging cables when seizing mobile devices?


A) Mobile device batteries have a limited charge life span, and the device will need a charger to maintain the battery until the device can be processed.
B) To reduce owner complaints about missing cables when, at some point, seized devices are returned.
C) In those cases where evidence seized is forfeit, you want to make sure you have everything you need to operate the device.
D) None of the above.

E) A) and B)
F) A) and D)

Correct Answer

verifed

verified

One of the difficulties in processing mobile devices is that the manufacturers always use proprietary storage formats.

A) True
B) False

Correct Answer

verifed

verified

The forensic examiner's best option for the most complete collection of data from a mobile device is to make a physical acquisition.

A) True
B) False

Correct Answer

verifed

verified

True

Best practices for seizing a mobile device is to power the device off and remove the battery so that no new connections are made over the network.

A) True
B) False

Correct Answer

verifed

verified

Which of the following is NOT one of the methods mobile devices use to communicate?


A) FDDI
B) Telecommunication networks
C) WiFi access points
D) Bluetooth piconets

E) C) and D)
F) A) and D)

Correct Answer

verifed

verified

Mobile devices have become a promising new target for malware developers.

A) True
B) False

Correct Answer

verifed

verified

Certain data on mobile devices, in particular phone numbers, are stored in "nibble reversed" format. In that case, the phone number 12025437078 would be displayed as:


A) 2120457370F8
B) 20217345870
C) 87073452021
D) 8F0737542021

E) A) and D)
F) None of the above

Correct Answer

verifed

verified

Discuss methodologies for processing a crime scene involving mobile devices. Take into account the special issues relating to mobile devices.

Correct Answer

verifed

verified

search for media and SIM cards, seizing related peripherals and communication cables, charging stands, etc., how to isolate the device from the network(s), powering off issues.

Certain data on mobile devices, particularly phone numbers, are stored in nibble-reversed format.

A) True
B) False

Correct Answer

verifed

verified

There are currently no forensic tools available for processing mobile devices.

A) True
B) False

Correct Answer

verifed

verified

Showing 1 - 20 of 32

Related Exams

Show Answer