
GIAC Advanced Smartphone Forensics
Domain 2Objective 1
Mobile Device File System Artifacts GASF Practice Questions (Page 1)
Part of the Mobile Device File System Analysis domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
4concepts
Questions 1–5
- 1
You are analyzing an Android device image. You find a file at '/data/system/netstats/'. What type of artifacts are stored in this directory and what can they reveal?
Select an answer first - 2
You are examining an Android device and find a file named 'com.android.chrome' in the /data/data directory. What does this file represent?
Select an answer first - 3
You are examining an iOS device backup (not a full file system image). You need to locate the SMS/MMS database to analyze message timestamps and content. Where would you expect to find this database within the backup structure?
Select an answer first - 4
You are preparing to document a file system artifact for a court case. Which of the following is the most appropriate way to record the artifact's location?
Select an answer first - 5
You are examining a file system image from an Android device. You find a SQLite database in /data/data/com.whatsapp/databases/msgstore.db. The 'messages' table has a column 'timestamp' that appears to be a Unix epoch in milliseconds. How should you interpret this timestamp?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.