Certs Vault
See all results for ""
Home Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
Sign in Create account

GIAC Advanced Smartphone Forensics GASF Exam Questions

Preparing for the GASF exam is simple with Certs Vault. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.

At Certs Vault, we keep our GASF practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.

Download Exam View Entire Exam
Page: 1 / 2
Question #1 (Topic: Demo Questions)

Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date.

What is the name of this advanced searching capability?

A.

Watchlist Editor

B.

Tags

C.

Timeline

D.

Event of Interest

Correct Answer: C
Explanation:

Physical Analyzer offers the Timeline feature to narrow down what happened on the smartphone during a specific time, type, party, etc.

This is commonly used to narrow down time periods. Data that is manually carved will not be shown here.

There is also an option to create a custom timeline specification.

Question #2 (Topic: Demo Questions)

Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?

A.

SMS/MMS

B.

Email

C.

Call Logs

D.

Photos

Correct Answer: B
Explanation:

Photos, SMS/MMS and call logs can be extracted from a logical acquisition of a non-jailbroken device. Once a device

has been jailbroken, email can be extracted for review

Question #3 (Topic: Demo Questions)

An Android device user is known to use Facebook to communicate with other parties under examination.


There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?

A.

com.android.chrome/app_chrome/Default/Local Storage

B.

dmappmgr.db

C.

/data/system/packages.xml

D.

AndroidManifest.xml

Correct Answer: B
Explanation:

Reference:https://www.ctsforensics.com/assets/news/35550_Web-update.pdf]

Question #4 (Topic: Demo Questions)

Which file, found natively on most Android devices, will contain location history such as coordinates,

physical addresses and timestamps?

A.

/data/data/com.google.android.apps.maps/databases/da_destination_history

B.

/data/data/com.google.android.apps.maps/databases/search_history.db

C.

/data/data/com.google.android.location/files/DATA_Preferences

D.

/data/data/com.vznavigator.ADR6300/databases/NIMSTORE.db

Correct Answer: B
Explanation:

[Reference:https://books.google.com.pk/books?id=zDibrpXTfxMC&pg=PA356&lpg=PA356&dq=data/data/, com.google

.android.apps.maps/databases/da_destination_history&source=bl&ots=-KA8ikP4r&,

sig=IM_QC11zGF73P3zi8Ds9LQb2eW8&hl=en&sa=X&ved=0ahUKEwjcrObe4J7aAhXENJoKHdSLCP0,

Q6AEILzAB#v=onepage&q=data%2Fdata%2Fcom.google.android.apps.maps%2Fdatabases

%, 2Fda_destination_history&f=false]

Question #5 (Topic: Demo Questions)

Cellebrite Physical Analyzer uses Bit Defender to scan for malware by flagging files who have known bad hash values.

This is an example of which type of mobile malware detection?

A.

Specific-based malware detection

B.

Signature-based detection

C.

Behavioral-based detection

D.

Cloud based malware detection

Next Question
Correct Answer: B
Explanation:

[Reference:https://security.stackexchange.com/questions/95186/what-is-the-precise-difference-

between-asignature-based-vs-behavior-based-antiv]