
GIAC Advanced Smartphone Forensics
Domain 3Objective 3
Apple Device Application Analysis GASF Practice Questions (Page 5)
Part of the Mobile Device Application Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 21–25
- 21
You are analyzing a third-party messaging app that claims to use end-to-end encryption. You need to recover the user's contacts and message metadata. The app stores data in a SQLite database and uses the Keychain for encryption keys. What is the most effective strategy?
Select an answer first - 22
What command-line tool is commonly used to examine the structure and contents of an iOS SQLite database?
Select an answer first - 23
In the iOS app sandbox, which directory is intended for user-generated content that should be backed up and is visible to the user through the Files app?
Select an answer first - 24
You are analyzing a third-party messaging app on an iOS device. You need to recover deleted messages and associated timestamps. Which combination of files should you examine?
Select an answer first - 25
In a forensic examination of an iOS device, you need to recover the user's saved passwords for a third-party banking app. The device is jailbroken and you have full file system access. Where should you focus your analysis to find these credentials?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.