100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

MDF FINAL EXAM 2024 QUESTIONS WITH COMPLETE SOLUTIONS!!

Rating
-
Sold
-
Pages
50
Grade
A+
Uploaded on
21-08-2024
Written in
2024/2025

MDF FINAL EXAM 2024 QUESTIONS WITH COMPLETE SOLUTIONS!!

Institution
MDF
Course
MDF

Content preview

MDF FINAL EXAM 2024
QUESTIONS WITH
COMPLETE
SOLUTIONS!!
MDF

Evatee 8/21/24 MDF

,MDF FINAL EXAM 2024 QUESTIONS WITH
COMPLETE SOLUTIONS!!


What is the term used extensively in the digital forensics community to qualify
and justify the use of a particular forensic technology or methodology? Answer
- Forensically Sound


List 3 mobile device operating systems. Answer - Android, iOS, Windows


Mobile forensics is a branch of digital forensics related to the recovery of digital
evidence from what types of devices? Answer - Cell Phones, GPS devices,
drones, tablets


What is a brief definition or translation of the term "metadata?" Answer -
"data about data"


What are SIM card data files? Answer - ICCID, IMSI, MSISDN


Metadata that can be specifically found in media files, such as pictures, is
known as? Answer - EXIF Data


What is the order of extraction methodologies from the bottom of the
"pyramid" to the top, with the bottom representing the most basic? Answer -
Manual, Logical, Hex Dump, Chip Off, Micro Read


Which of the following is not an example of a Hex Dump Extraction: File
system, Bootloader Physical, Client Physical, JTAG Answer - File System

,An examiner would physically scroll through a device while photographically
documenting its screen during what type of acquisition? Answer - Manual


What does a logical acquisition utilize Answer - a device's API, and is achieved
through USB or Bluetooth connections.


Physical acquisitions directly access what Answer - the flash memory of a
mobile device, resulting in a bit-for-bit copy of the data.


What will never be recovered through a logical acquisition? Answer -
Unallocated space


The mobile forensics process is broken down in to what three main categories?
Answer - Seizure, acquisition, and examination/analysis


Search warrants require what? Answer - Scope, Oath/Affirmation, Probable
Cause


At the crime scene, the examiner should place the device in _______ and/or a
_______ to prevent changes to the mobile device. Answer - Airplane mode,
faraday bag


Describe 1 way of identifying the model of an iPhone, and 1 way of identifying
the iOS version of an iPhone. Answer - Model of iPhone: looking at the
back/bottom half of the phone @ A#; iOS version: unlock
phone>settings>general>about


iOS devices utilize what file systems? Answer - HFSX

, Within the file system of Apple mobile devices, which partition contains the
device firmware, the operating system, and pre-installed application settings
that are not typically available to the device user? Answer - System Partition


What Apple protocol prevents users from downloading and installing
unauthorized apps? Answer - Code Signing


What is the iOS architecture layer that develops the visual interface, provides
basic application architecture, and supports key functions, such as multi-
tasking? Answer - Cocoa Touch


What does sandboxing do? Answer - Requires user permission in order to
allow applications to access data from other applications


What are the Apple mobile device modes? Answer - DFU, Normal, Recovery


What iOS backup is utilized when conducting an Advanced Logical acquisition in
Cellebrite Physical Analyzer? Answer - Method 1 = iTunes Backup, Method 2 =
Apple File Conduit


What property list file, located in an iTunes backup, contains metadata
regarding application backup, identifying, and encryption-related information,
such as application names, passcode/encryption status, and keybagdata?
Answer - Manifest.plist


What are pairing records? Answer - The records of every time you've
connected your phone to your computer and had your phone "trust" it


Devices that utilize iOS or OSX operating systems store timestamps in what raw
format? Answer - Mac Absolute Time and Unix Epoch Time

Written for

Institution
MDF
Course
MDF

Document information

Uploaded on
August 21, 2024
Number of pages
50
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

  • metadata that can b

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EvaTee Phoenix University
View profile
Follow You need to be logged in order to follow users or courses
Sold
5124
Member since
4 year
Number of followers
3564
Documents
53810
Last sold
1 day ago
TIGHT DEADLINE? I CAN HELP

Many students don\'t have the time to work on their academic papers due to balancing with other responsibilities, for example, part-time work. I can relate. kindly don\'t hesitate to contact me, my study guides, notes and exams or test banks, are 100% graded

3.8

935 reviews

5
445
4
165
3
170
2
47
1
108

Trending documents

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions