
GIAC Advanced Smartphone Forensics
Domain 3Objective 3
Apple Device Application Analysis GASF Practice Questions (Page 7)
Part of the Mobile Device Application Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 31–35
- 31
You are analyzing an encrypted iTunes backup of an iPhone. After successfully decrypting the backup, you need to locate the SQLite database for a messaging app. What is the most reliable method to find the correct database file within the backup?
Select an answer first - 32
You are analyzing a WhatsApp backup from an iOS device. You need to recover chat history and associated media metadata. Which files should you prioritize in your analysis?
Select an answer first - 33
What type of file is commonly used by iOS apps for logging events and errors, and can be analyzed to reconstruct user actions?
Select an answer first - 34
You are analyzing an encrypted iTunes backup of an iPhone. The backup password is known, but you cannot extract Keychain items. The device itself is not available. What is the most likely reason for this limitation?
Select an answer first - 35
You are investigating a case involving a social media app. The user has deleted several photos from the app's cache. You have a full file system image. Which technique is most likely to recover the deleted photos?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.