Chapter 19 - Digital/Multimedia Forensics Flashcards

Cell Phones, Video, and Audio (46 cards)

1
Q

Early mobile phone systems were followed by digital _____ networks.

A

2G

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: The architectural functionality that distinguishes 2G from 3G is that 2G systems were circuit switched and 3G systems are packet switched.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False: One of the benefits of packet switching is the ability to connect more readily to the Internet.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

It’s (easy, difficult ) to stay current with the available mobile device models.

A

difficult

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Apple has taken major steps to standardize the development of apps for its and _____ .

A

iPad; iPhone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Some devices and many apps report the _____ of the device. That can make it much easier to track the owner’s movements.

A

geolocation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When working on a mobile device, there are several sources of information available to the investigator. Probably the most useful source of information available to an investigator is _____ .

A

Web searching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An examiner should decide whether to obtain a _____ extraction or _____ extraction or both of a mobile device.

A

physical; logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

T or F: If you have a device that supports physical extraction, that is the way to image the device. Logical extractions are useful only when the physical option is not available because of the device itself.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

T or F: physical extractions are bit-by-bit copies of the file system including deleted data.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Examiners make it a practice to run an extracted image (once, twice).

A

twice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The _____ extraction is fairly fast and one might want to examine it for obvious evidence while a tool is making a physical image of the target.

A

logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Just like computers, the _____ defines the basic components of the mobile device.

A

architecture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

_____ are storage expansion cards that many mobile devices can accept.

A

SD or secure digital cards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SD cards are “nonvolatile,” meaning that even if the power is turned off on the device, you won’t lose your favorite tunes or your pictures.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In many cases, you can keep your subscriber information when you change mobile phones by simply switching the _____ card to the new phone.

A

SIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Often it is desirable to _____ the SIM in much the same way as one would take a physical image of the mobile device or a computer in order to retain a copy for evidentiary purposes.

A

clone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

T or F: It’s always possible to recover deleted file items such as e-mails, texts, and photos from a mobile device.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

_____ describes the events and concomitant evidence that make up the events of the crime.

A

chain of evidence

20
Q

_____ chains show events in the order in which they occurred.

21
Q

_____ chains of evidence describe the events of a crime in terms of cause and effect.

22
Q

_____ crime assessment attempts to tie elements of a crime together into a single crime scene and use the timelines to build a picture and describe the events and supporting evidence of the crime.

23
Q

It is likely that the mobile device is extremely accurate as a yardstick for measuring when events happen as the device may be synchronized to a _____ clock.

24
Q

When a mobile device is set to use _____ , it will recognize any _____ network in its range.

25
T or F: Mobile device forensic analysis can provide an overlay to physical evidence, and timelines (as well as computer forensic timelines) can give a clearer picture of the events preceding and following a crime event.
True
26
What are the 1G highlights?
-analog networks -only cell towers -no WiFi
27
A mobile device is made up of:
a computer and one or more radios.
28
2G _____ could do more than simple outgoing incoming calls.
feature phones
29
What are the 2G highlightrs?
-send/receive SMS (text) -synch with e-mail -No web surfing -No ability to send photos -blackberry
30
What is the distinction between 2G and 3G?
2G = circuit switched (landline) 3G = packet switched (internet)
31
4G or native IP network features:
access internet directly, increasing speed and bandwidth
32
What phones are the closest in architecture and design to a PC?
3G, 4G, 5G phones
33
A snapshot of the same view that the user gets is a _____.
logical extraction
34
Whats the acronym for SIM card
subscriber identity module
35
Working on what type of surface increases the danger of static electricity?
carpet
36
When working on electronic devices, what should you use to dissipate any static charge that might damage electronic chips?
Grounded anti-static wristband
37
SIM stands for:
subscriber identity module.
38
What would an investigator do the SIM card to retain a perfect copy for evidentiary purposes?
Clone the SIM
39
What does the ICCID contain?
IIN (issuer identification number)
40
What feature on a mobile device can help an investigator establish a timeline?
GPS
41
It may not be possible to recover deleted file items from a mobile device such as emails, texts and photos.
True
42
SD cards and SIM cards perform the same way.
False
43
Even though some mobile devices are really small computers with computer-like operating systems, they usually can be examined using typical computer forensic tools.
False
44
The amount of information we can get from a mobile device varies greatly with the device in question.
true
45
Secure Digital (SD) cards are storage expansion cards that many mobile devices can accept. The SD card adds memory for storing such things as photos and music. SD cards are nonvolatile.
True
46