
GIAC Advanced Smartphone Forensics
The GIAC Advanced Smartphone Forensics (GASF) certification validates a practitioner's ability to perform expert-level forensic examinations on mobile phones and tablets. It covers the fundamentals of mobile forensics, device file system analysis, mobile application behavior, event artifact analysis, and the identification and analysis of mobile device malware. This credential is designed for experienced digital forensic examiners, incident responders, and law enforcement professionals who need to deliver reliable, court-defensible analysis from mobile devices.
342 practice questions · Updated 2026-07-30
GASF Curriculum
Every domain, objective, and concept the GASF exam measures.
- Definition and Scope of Mobile Forensics
- Mobile Device Types and Characteristics
- Forensic Process Overview
- Legal and Ethical Considerations
- Challenges in Mobile Forensics
- File System Artifact Identification
- Artifact Location and Structure
- Artifact Interpretation
- Artifact Preservation and Documentation
- Android file system hierarchy
- User data partition artifacts
- Application data storage
- SQLite database analysis
- Android log files
- Cache and temporary files
- Media and file metadata
- Deleted file recovery
- File system journaling and wear leveling
- Android backup artifacts
- Cloud and synchronization artifacts
- Encryption and key handling
- Apple File System (APFS) Structure
- HFS+ Legacy File System
- iOS Filesystem Hierarchy
- Key iOS Artifact Locations
- Property List (plist) Analysis
- SQLite Database Forensics
- Apple Metadata and Timestamps
- Deleted File Recovery on Apple Devices
- Encryption and Data Protection
- Mobile Device Management (MDM) Artifacts
- Application Data Storage Locations
- Application Artifact Extraction
- Application Data Analysis
- Application Metadata Examination
- Application-Specific Forensic Techniques
- Application Data Correlation
- Application Security and Encryption
- Application Data Recovery
- Application Data Validation and Verification
- Application Data Reporting
- Android App Data Storage Locations
- Android App Sandboxing and Permissions
- Analyzing Android App Databases
- Analyzing Android App Shared Preferences and Caches
- Recovering Deleted Data from Android Apps
- Correlating App Data with User Activity
- Android App Artifacts in Backups and Cloud
- Apple App Data Storage Locations
- Apple App Backup Analysis
- Apple App Plist File Analysis
- Apple App SQLite Database Analysis
- Apple App Cache and Log File Analysis
- Apple App Keychain Analysis
- Apple App Third-Party Application Artifacts
- Apple App Deleted Data Recovery
- Malware Types on Mobile Devices
- Malware Infection Vectors
- Malware Behavior Analysis
- Static Malware Analysis Techniques
- Dynamic Malware Analysis Techniques
- Mobile Malware Detection Tools
- Reverse Engineering Mobile Malware
- Malware Persistence and Evasion Techniques
- Network Traffic Analysis for Malware
- Mobile Malware Forensic Investigation
- Mitigation and Remediation Strategies
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GASF, so none is invented.