
GIAC Advanced Smartphone Forensics
Domain 3Objective 1
Mobile Device Application Analysis GASF Practice Questions (Page 9)
Part of the Mobile Device Application Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
10concepts
Questions 41–44
- 41
What is the primary purpose of application-level encryption on a mobile device?
Select an answer first - 42
During a forensic examination of an Android device, you need to recover a suspect's chat history from a messaging app that stores its database in the app's sandboxed internal storage. The device is rooted, and you have a full filesystem image. Which approach best preserves the integrity of the database while allowing you to analyze its contents?
Select an answer first - 43
You are analyzing a suspect's device and find a social media app with a 'posts' table containing 'content', 'timestamp', and 'location' columns. You also have the suspect's GPS data from a fitness app and call detail records (CDRs) from the carrier. You need to determine if the suspect was at a specific location when a particular post was made. Which approach is most reliable?
Select an answer first - 44
You have extracted a database from a suspect's smartphone and need to ensure the data is admissible in court. Which step is most important to verify the integrity and authenticity of the extracted data?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GASF
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.