
GIAC Advanced Smartphone Forensics
Domain 2Objective 2
Android Device File System Artifacts GASF Practice Questions (Page 9)
Part of the Mobile Device File System Analysis domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
12concepts
Questions 41–45
- 41
In a standard Android device file system hierarchy, which partition is mounted read-only and contains the core operating system files that are common to all devices of a given model?
Select an answer first - 42
An examiner is analyzing a SQLite database from an Android app and finds that the database has a write-ahead log (WAL) file. The examiner wants to recover data that was recently deleted from the main database. Which approach is most effective?
Select an answer first - 43
When analyzing a SQLite database from an Android device, which of the following is a common technique to recover deleted records?
Select an answer first - 44
An examiner has an Android backup file created by the 'adb backup' command. The examiner wants to extract the data for a specific app. Which tool or method is most appropriate?
Select an answer first - 45
Which of the following is a common type of temporary file that forensic examiners might find in cache directories and that can reveal user activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.