⏰ Hurry! Limited-Time 20% Savings on Premium Certification Materials - Coupon code: Club20
Certs Club
See all results for ""
Home Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
Sign in Get Started

GIAC Advanced Smartphone Forensics GASF Exam Questions

Download Exam View Entire Exam
Page: 1 / 2
Question #1 (Topic: Demo Questions)

Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date.

What is the name of this advanced searching capability?

A.

Watchlist Editor

B.

Tags

C.

Timeline

D.

Event of Interest

Correct Answer: C
Explanation:

Physical Analyzer offers the Timeline feature to narrow down what happened on the smartphone during a specific time, type, party, etc.

This is commonly used to narrow down time periods. Data that is manually carved will not be shown here.

There is also an option to create a custom timeline specification.

Question #2 (Topic: Demo Questions)

Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?

A.

SMS/MMS

B.

Email

C.

Call Logs

D.

Photos

Correct Answer: B
Explanation:

Photos, SMS/MMS and call logs can be extracted from a logical acquisition of a non-jailbroken device. Once a device

has been jailbroken, email can be extracted for review

Question #3 (Topic: Demo Questions)

An Android device user is known to use Facebook to communicate with other parties under examination.


There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?

A.

com.android.chrome/app_chrome/Default/Local Storage

B.

dmappmgr.db

C.

/data/system/packages.xml

D.

AndroidManifest.xml

Correct Answer: B
Explanation:

Reference:https://www.ctsforensics.com/assets/news/35550_Web-update.pdf]

Question #4 (Topic: Demo Questions)

Which file, found natively on most Android devices, will contain location history such as coordinates,

physical addresses and timestamps?

A.

/data/data/com.google.android.apps.maps/databases/da_destination_history

B.

/data/data/com.google.android.apps.maps/databases/search_history.db

C.

/data/data/com.google.android.location/files/DATA_Preferences

D.

/data/data/com.vznavigator.ADR6300/databases/NIMSTORE.db

Correct Answer: B
Explanation:

[Reference:https://books.google.com.pk/books?id=zDibrpXTfxMC&pg=PA356&lpg=PA356&dq=data/data/, com.google

.android.apps.maps/databases/da_destination_history&source=bl&ots=-KA8ikP4r&,

sig=IM_QC11zGF73P3zi8Ds9LQb2eW8&hl=en&sa=X&ved=0ahUKEwjcrObe4J7aAhXENJoKHdSLCP0,

Q6AEILzAB#v=onepage&q=data%2Fdata%2Fcom.google.android.apps.maps%2Fdatabases

%, 2Fda_destination_history&f=false]

Question #5 (Topic: Demo Questions)

Cellebrite Physical Analyzer uses Bit Defender to scan for malware by flagging files who have known bad hash values.

This is an example of which type of mobile malware detection?

A.

Specific-based malware detection

B.

Signature-based detection

C.

Behavioral-based detection

D.

Cloud based malware detection

Next Question
Correct Answer: B
Explanation:

[Reference:https://security.stackexchange.com/questions/95186/what-is-the-precise-difference-

between-asignature-based-vs-behavior-based-antiv]