Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Advanced Smartphone Forensics

Domain 4Objective 1

Mobile Device Malware Analysis GASF Practice Questions (Page 6)

Part of the Mobile Device Malware Analysis domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 8–12 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
11concepts

Questions 26–30

  1. 26foundation · easy

    A mobile security analyst discovers an app that displays intrusive full-screen ads and collects user location data without clear consent. Which type of mobile malware best describes this behavior?

    Select an answer first
  2. 27expert · hard

    A forensic examiner is investigating a suspected spyware infection on an Android device. The device is rooted, and the examiner has full filesystem access. The examiner finds a suspicious app in /system/app/ that is not present in the user's app list. The app's APK is signed with the platform key. The examiner also finds a file in /data/data/com.suspicious.app/ that contains logs of keystrokes. Which forensic finding is the STRONGEST indicator that the app is spyware?

    Select an answer first
  3. 28foundation · easy

    Which technique is used by mobile malware to hide its malicious code from static analysis tools?

    Select an answer first
  4. 29foundation · easy

    A malware analyst wants to observe the runtime behavior of a suspicious mobile app, including its network communications and file system interactions. Which analysis approach should they use?

    Select an answer first
  5. 30application · medium

    During dynamic analysis of a mobile trojan, the analyst observes that the app makes a DNS query for a domain that is not registered. The app then attempts to connect to an IP address that is not responding. The analyst suspects the malware is using a domain generation algorithm (DGA). Which observation would confirm this suspicion?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASF” is a trademark of its owner, used for identification only.