
GIAC Advanced Smartphone Forensics
Domain 2Objective 1
Mobile Device File System Artifacts GASF Practice Questions (Page 2)
Part of the Mobile Device File System Analysis domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
4concepts
Questions 6–10
- 6
You are investigating a case involving an iPhone. You have a file system image. You find a SQLite database in the 'Library/SMS' directory named 'sms.db'. The 'message' table has a column 'date' that appears to be a Unix epoch in seconds. You also find a 'date_read' column. How should you interpret these timestamps to reconstruct the user's messaging activity?
Select an answer first - 7
What is the primary purpose of interpreting file system artifacts in a forensic examination?
Select an answer first - 8
Which of the following best describes the hierarchical organization of file system artifacts on a mobile device?
Select an answer first - 9
You are analyzing an iOS device image. You find a file named 'com.apple.locationd.plist' in the mobile/Library/Preferences/ directory. What type of artifact is this and what can it reveal?
Select an answer first - 10
You are examining an iOS backup and need to find the user's voicemail messages. Which domain and path would you look in?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.