
GIAC Advanced Smartphone Forensics
Domain 2Objective 3
Apple Device File System Artifacts GASF Practice Questions (Page 7)
Part of the Mobile Device File System Analysis domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
10concepts
Questions 31–35
- 31
An examiner is working with an older iPhone running iOS 9, which uses HFS+. The device has been seized and the examiner needs to recover deleted files. The device was not jailbroken. Which technique is most appropriate for recovering deleted files from this HFS+ volume?
Select an answer first - 32
You are analyzing an iOS 15 device image. You need to locate the user's downloaded applications and their data. Which directory path would you examine?
Select an answer first - 33
You are analyzing a plist file that contains a timestamp value of 700000000. You need to convert this to a human-readable date. Which reference date should you use?
Select an answer first - 34
A forensic examiner has a logical acquisition of an iOS device that is passcode-locked. The acquisition includes the filesystem, but many app data files appear encrypted. The examiner needs to access the contents of a specific app's SQLite database. Which approach is most viable?
Select an answer first - 35
Which tool or command is commonly used to convert a binary plist to a human-readable XML format on macOS?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GASF
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.