Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Advanced Smartphone Forensics

Domain 3Objective 2

Android Device Application Analysis GASF Practice Questions (Page 4)

Part of the Mobile Device Application Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 16–20

  1. 16application · medium

    During a forensic examination of a rooted Android device, you need to recover deleted chat messages from a messaging app. The app stores its data in an encrypted SQLite database within its sandboxed internal storage. You have obtained a full physical image and the device is rooted. Which approach is most likely to yield the deleted messages?

    Select an answer first
  2. 17expert · hard

    An examiner is reconstructing a suspect's activities from a travel app and a calendar app. The travel app stores flight bookings in a SQLite database, while the calendar app stores events in a separate SQLite database. Both apps sync to cloud services. The examiner has access to the device and the cloud accounts. Which approach would best reconstruct the suspect's travel timeline?

    Select an answer first
  3. 18expert · hard

    An examiner is trying to recover deleted photos from a gallery app on an Android device. The app stores thumbnails in a SQLite database and full images in external storage. The database has been vacuumed, and the external storage has been partially overwritten. Which technique is most likely to recover the deleted photos?

    Select an answer first
  4. 19application · medium

    During a forensic examination of a suspect's Android device, you locate the package directory for a messaging app. The app's SQLite database file appears to have been recently deleted from its original location. Which approach would most likely recover the deleted database content?

    Select an answer first
  5. 20expert · hard

    A forensic examiner is analyzing a banking app on an Android device. The app uses a SQLite database that is encrypted with SQLCipher. The examiner has root access and can extract the database file, but the encryption key is not stored in shared preferences. The app uses the Android Keystore to protect the key. Which approach is most likely to succeed in decrypting the database?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.