GIAC Advanced Smartphone Forensics GASF Exam Questions
Preparing for the GASF exam is simple with Certs Vault. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.
At Certs Vault, we keep our GASF practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.
Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date.
What is the name of this advanced searching capability?
Correct Answer: C
Physical Analyzer offers the Timeline feature to narrow down what happened on the smartphone during a specific time, type, party, etc.
This is commonly used to narrow down time periods. Data that is manually carved will not be shown here.
There is also an option to create a custom timeline specification.
Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?
Correct Answer: B
Photos, SMS/MMS and call logs can be extracted from a logical acquisition of a non-jailbroken device. Once a device
has been jailbroken, email can be extracted for review
An Android device user is known to use Facebook to communicate with other parties under examination.
There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?
Correct Answer: B
Reference:https://www.ctsforensics.com/assets/news/35550_Web-update.pdf]
Which file, found natively on most Android devices, will contain location history such as coordinates,
physical addresses and timestamps?
Correct Answer: B
[Reference:https://books.google.com.pk/books?id=zDibrpXTfxMC&pg=PA356&lpg=PA356&dq=data/data/, com.google
.android.apps.maps/databases/da_destination_history&source=bl&ots=-KA8ikP4r&,
sig=IM_QC11zGF73P3zi8Ds9LQb2eW8&hl=en&sa=X&ved=0ahUKEwjcrObe4J7aAhXENJoKHdSLCP0,
Q6AEILzAB#v=onepage&q=data%2Fdata%2Fcom.google.android.apps.maps%2Fdatabases
%, 2Fda_destination_history&f=false]
Cellebrite Physical Analyzer uses Bit Defender to scan for malware by flagging files who have known bad hash values.
This is an example of which type of mobile malware detection?
Correct Answer: B
[Reference:https://security.stackexchange.com/questions/95186/what-is-the-precise-difference-
between-asignature-based-vs-behavior-based-antiv]