GIAC Advanced Smartphone Forensics (GASF) Free Practice Test
Question 1
Which of the following items is found in the Kernel Space for an iOS device?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 2
When conducting forensic analysis of an associated media card, one would most often expect to find this particular file system format?
Correct Answer: D
Question 3
An analyst investigating a Nokia S60 Symbian device wants to know if an Adobe Flash file on the handset is compromised.

Which file in the image will best target the Adobe Flash files?

Which file in the image will best target the Adobe Flash files?
Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 4
Where would an examiner find evidence of an iOS update to device from one version to another?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 5
An analyst is reviewing the contents of a media card that was found without an associated device. Based on the image below, with which mobile device is it most likely that this device was once paired?


Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 6
What information can you determine by reviewing the (bp2p) file from a BlackBerry OS10 handset?


Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 7
Which of the following files contains details regarding the encryption state of an iTunes backup file?
Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 8
Which of the following actions described below would populate the suggestions table on an Android phone?
Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).