
GIAC Advanced Smartphone Forensics
Domain 2Objective 1
Mobile Device File System Artifacts GASF Practice Questions (Page 5)
Part of the Mobile Device File System Analysis domain, which makes up ~37% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
4concepts
Questions 21–25
- 21
You are documenting a file system artifact found on a mobile device. Which of the following is the most important information to record?
Select an answer first - 22
You are examining a file system image from an iPhone. You find a file named 'com.apple.MobileSMS.plist' in the mobile/Library/Preferences/ directory. What does this artifact reveal?
Select an answer first - 23
During an iOS forensic examination, you find a plist file that contains a list of recently opened documents. Which type of artifact is this?
Select an answer first - 24
You are analyzing an Android device and find a file named 'com.facebook.katana' in the /data/data directory. What does this file represent?
Select an answer first - 25
Why is it important to document file system artifacts during a forensic examination?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.