
GIAC Advanced Smartphone Forensics
Domain 4Objective 1
Mobile Device Malware Analysis GASF Practice Questions (Page 11)
Part of the Mobile Device Malware Analysis domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 8–12 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
11concepts
Questions 51–53
- 51
A security analyst is triaging a suspicious iOS app binary obtained from a third-party app store. The analyst needs to determine whether the app contains known malicious code without executing it. Which tool or technique is most appropriate for this initial triage?
Select an answer first - 52
Which reverse engineering technique involves converting a compiled Android app (APK) back into readable source code?
Select an answer first - 53
During a forensic investigation of a compromised Android device, the examiner finds a malicious app that has been deleted from the device. The examiner has a full filesystem image. The app's package name is known, and the examiner needs to recover evidence of the app's installation and behavior. Which forensic approach is most likely to yield the most useful artifacts?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GASF
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.