Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

GASF GIAC Advanced Smartphone Forensics Questions and Answers

Questions 4

Which of the following items is found in the Kernel Space for an iOS device?

Options:

A.

Cocoa Touch framework

B.

System Area

C.

Applications

D.

Core Services

Buy Now
Questions 5

Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date.

What is the name of this advanced searching capability?

Options:

A.

Watchlist Editor

B.

Tags

C.

Timeline

D.

Event of Interest

Buy Now
Questions 6

What is often more of a challenge with mobile forensics than other areas of forensics?

Options:

A.

Analysis and Reporting of Information

B.

Isolation of devices

C.

Identification of evidence

D.

Evidence collection

Buy Now
Questions 7

While conducting forensic analysis of an associated media card, one would most often expect to find this particular file system format?

Options:

A.

HFS

B.

NTFS

C.

Yaffs2

D.

FAT

Buy Now
Questions 8

When conducting forensic analysis of an associated media card, one would most often expect to find this

particular file system format?

Options:

A.

HFS

B.

NTFS

C.

Yaffs2

D.

FAT

Buy Now
Questions 9

Property list (Plist) files are used by iOS devices to store datA. Which of the file formats below is common to

plist files?

Options:

A.

HTML

B.

SQL

C.

DMG

D.

Binary

Buy Now
Questions 10

What information can you determine by reviewing the (bp2p) file from a BlackBerry OS10 handset?

GASF Question 10

Options:

A.

Cloud accounts

B.

Bluetooth pairings

C.

Paired computers

D.

Connected Wireless Access points

Buy Now
Questions 11

Which of the following is one potential risk of using the ALWAYS OFF rule for handling cell phones?

Options:

A.

Overwriting data

B.

Engaging password or PIN protection mechanism

C.

Destruction of call logs and cell tower information

D.

Improper handling by the user

Buy Now
Questions 12

Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?

Options:

A.

SMS/MMS

B.

Email

C.

Call Logs

D.

Photos

Buy Now
Questions 13

How would an examiner review items deleted from a SQLITE database?

Options:

A.

Using a Hex Viewer

B.

Converting the database to a txt file

C.

Reviewing the file header

D.

Selecting the raw data from the table

Buy Now
Questions 14

What type of acquisition has occurred for this device?

GASF Question 14

Options:

A.

Physical

B.

File system

C.

Bypass lock

D.

Logical

Buy Now
Questions 15

An Android device user is known to use Facebook to communicate with other parties under examination.

There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?

Options:

A.

com.android.chrome/app_chrome/Default/Local Storage

B.

dmappmgr.db

C.

/data/system/packages.xml

D.

AndroidManifest.xml

Buy Now
Questions 16

Which artifact must be carved out manually when examining a file system acquisition of an Android device?

Options:

A.

Deleted images

B.

Contacts

C.

SMS messages

D.

Phone numbers

Buy Now
Questions 17

Which of the following files contains details regarding the encryption state of an iTunes backup file?

Options:

A.

Keychain-backup.plist

B.

Manifest.mbdb

C.

Manifest.plist

D.

Status.plist

Buy Now
Questions 18

Which file, found natively on most Android devices, will contain location history such as coordinates, physical addresses and timestamps?

Options:

A.

/data/data/com.google.android.apps.maps/databases/da_destination_history

B.

/data/data/com.google.android.apps.maps/databases/search_history.db

C.

/data/data/com.google.android.location/files/DATA_Preferences

D.

/data/data/com.vznavigator.ADR6300/databases/NIMSTORE.db

Buy Now
Questions 19

What does the data string highlighted in blue represent in the File system path?

GASF Question 19

Options:

A.

Code name and build number

B.

Phone nick name and serial number

C.

Device user name and phone number

D.

Volume name and network ID

Buy Now
Questions 20

While analysis in BlackBerry application list it appears that no third-party applications were installed on the device. Which other file may provide you with additional information on applications that were accessed with the handset?

Options:

A.

BlackBerry NV Items

B.

Content Store

C.

Event logs

D.

BBThumbs.dat

Buy Now
Questions 21

Which of the following files provides the most accurate reflection of the device’s date/timestamp related to the

last device wipe?

Options:

A.

/private/var/mobile/Library/AddressBook/AddressBook.sqlitedb

B.

/private/var/mobile/Applications/com.apple.mobilesafari/Library/history.db

C.

/private/var/mobile/Applications/com.viber/Library/Prefernces/com.viber.plist

D.

/private/var/mobile/Applications/net.whatsapp.WhatsApp/Library/pw.dat

Buy Now
Questions 22

Cellebrite Physical Analyzer uses Bit Defender to scan for malware by flagging files who have known bad hash values. This is an example of which type of mobile malware detection?

Options:

A.

Specific-based malware detection

B.

Signature-based detection

C.

Behavioral-based detection

D.

Cloud based malware detection

Buy Now
Exam Code: GASF
Exam Name: GIAC Advanced Smartphone Forensics
Last Update: Apr 30, 2026
Questions: 75

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now GASF testing engine

PDF (Q&A)

$43.57  $124.49
buy now GASF pdf