Skip to main content

GASF Online Exam

GIAC Advanced Smartphone Forensics (GASF)

79 questions available ยท Page 1 of 8

View study plans
Question 1 Single choice

Review the information contained within the Viber application running on an Android device.

Which of the following can be determined?

  1. A

    A message containing the string 8901260572525158741 was sent using the Viber application.

  2. B

    The Viber account used to send/receive messages can be tied to the user in possession of the SIM card with an IMSI of 8901260572525158741

  3. C

    The user account for Viber is 8901260572525158741

  4. D

    The Viber account used to send/receive messages can be tied to the user in possession of the SIM card with an ICCID of 8901260572525158741

Show answer and explanation

Correct answer: D

Question 2 Single choice

Which iOS backup file will contain the last time the device was backed up?

  1. A

    notes.sqlite

  2. B

    manifest.mbdb

  3. C

    status.plist

  4. D

    info.plist

Show answer and explanation

Correct answer: D

Question 3 Single choice

You have conducted a keyword search over flash.bin and notice that multiple instances of the same data appear many times throughout the flash image.

What is this an example of?

  1. A

    Flash Translation Layer (FTL)

  2. B

    Logical Block Addressing (LBA)

  3. C

    NAND degradation

  4. D

    Wear-leveling

Show answer and explanation

Correct answer: C

Question 4 Single choice

An analyst is investigating files on a Nokia S60 Symbian device and looking for data that would contain possible cell tower locations, date and time stamps, phone numbers and/or references to files saved on the device.

Which of the follow files would contain user data that was created and stored on the device that meet this criteria?

  1. A

    MapView.r08

  2. B

    LifeblogCOUNTRYSTRINGS.r1 3

  3. C

    Lifeblog.db

  4. D

    PbkView.r03

Show answer and explanation

Correct answer: C

Question 5 Single choice

Using an emulator and running an application through a series of processes to figure out how it would behave on an actual device is called:

  1. A

    Forensic analysis

  2. B

    Dynamic analysis

  3. C

    Web analysis

  4. D

    Static analysis

Show answer and explanation

Correct answer: B

Question 6 Single choice

Which file type below is commonly associated with locational data and is an export option from within Cellebrite Physical Analyzer and XRY to provide detailed visual output of geographic information?

  1. A

    .plist

  2. B

    .kml

  3. C

    .xry

  4. D

    .ipa

Show answer and explanation

Correct answer: B

Question 7 Single choice

Which file system is mostly found on Samsung devices?

  1. A

    Yet Another Flash File System (YAFFS2)

  2. B

    Out of Bound (OOB)

  3. C

    Robust File system (RFS)

  4. D

    EXT4

Show answer and explanation

Correct answer: C

Question 8 Single choice

Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?

  1. A

    SMS/MMS

  2. B

    Email

  3. C

    Call Logs

  4. D

    Photos

Show answer and explanation

Correct answer: B

Question 9 Single choice

Which file, located on the Android file system, may be examined to correlate files related to external SD cards that were once used in an Android device?

  1. A

    Internal.db

  2. B

    Main.db

  3. C

    DataManager. Db

  4. D

    external.db

Show answer and explanation

Correct answer: D

Question 10 Single choice

Examine the unpacked Android application below.

Which important file, resident in most Android applications, is missing?

  1. A

    dalvik-cache

  2. B

    classes.dex

  3. C

    com.skype.raider-1.apk

  4. D

    classes-dex2jar.jar

Show answer and explanation

Correct answer: B