
GIAC Advanced Smartphone Forensics
Domain 3Objective 2
Android Device Application Analysis GASF Practice Questions (Page 1)
Part of the Mobile Device Application Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 1–5
- 1
A forensic examiner is investigating a suspect's Android device and finds that the suspect used a third-party backup app to back up app data to Google Drive. Which approach would best help the examiner identify and analyze app data artifacts in the cloud backup?
Select an answer first - 2
Which of the following is a common source of cloud-synced app data that a forensic examiner might analyze?
Select an answer first - 3
Which Android storage location is typically used for app-specific files that are large or intended to be shared with other apps, and is accessible without root?
Select an answer first - 4
During a forensic review of a ride-sharing app, you find a shared preferences XML file containing a timestamp for the last trip and a cache file with map tiles. How can you best use these artifacts to reconstruct the user's activity timeline?
Select an answer first - 5
During a forensic examination, you find that a social media app has a large cache directory. You suspect that the cache contains deleted images that were viewed by the user. Which action is most appropriate to recover these images?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.