
GIAC Advanced Smartphone Forensics
Domain 3Objective 1
Mobile Device Application Analysis GASF Practice Questions (Page 5)
Part of the Mobile Device Application Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
10concepts
Questions 21–25
- 21
Which of the following is a characteristic of shared storage on a mobile device?
Select an answer first - 22
You have extracted a database from a suspect's phone and need to present it in court. The defense argues that the database may have been altered during extraction. Which evidence would best refute this claim?
Select an answer first - 23
You are examining a productivity app on a suspect's device that stores documents in a proprietary format. The app also has a companion cloud service. You have extracted the app's local data. What is the most effective way to analyze the documents?
Select an answer first - 24
You are investigating a case where a suspect deleted a messaging app and its data from an Android device. You have a physical image of the device. The app used a SQLite database in its sandboxed directory. You also have a cloud backup from the suspect's account that contains an older version of the app's database. Which combination of techniques is most likely to recover the most complete set of messages?
Select an answer first - 25
Why is it important to document the hash values of application data in a forensic report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.