Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

GASF Exam Dumps - GIAC Security Certification: GASF Questions and Answers

Question # 4

What is being shown in the image below?

Options:

A.

An outgoing call that was not answered

B.

A call that was answered but immediately hung up

C.

A missed Skype message on an android device

D.

A call that was answered and lasted 5 seconds

Buy Now
Question # 5

Cellebrite’s Physical Analyzer will conduct a Quick Scan for images, which goes through and carves files that may have been deleted from the device. When carving for image files, which of the following methods is most effectively used to recover data?

Options:

A.

Update the signature database

B.

Carve based on file header

C.

Carve based on file metadata

D.

Carve based on memory ranges

Buy Now
Question # 6

Based on the image below, which file system is being examined?

Options:

A.

Chinese knock-off

B.

Windows

C.

Android

D.

Blackberry

Buy Now
Question # 7

An Android device user is known to use Facebook to communicate with other parties under examination.

There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?

Options:

A.

com.android.chrome/app_chrome/Default/Local Storage

B.

dmappmgr.db

C.

/data/system/packages.xml

D.

AndroidManifest.xml

Buy Now
Question # 8

Which artifact must be carved out manually when examining a file system acquisition of an Android device?

Options:

A.

Deleted images

B.

Contacts

C.

SMS messages

D.

Phone numbers

Buy Now
Question # 9

Exhibit:

Where can an analyst find data to provide additional artifacts to support the evidence in the highlighted file?

Options:

A.

internal.db-wal

B.

browser2.db

C.

sysmon2.db-shm

D.

external.db

Buy Now
Question # 10

What does access to iOS DFU mode provide an examiner?

Options:

A.

Ability to decrypt the SD card of a Symbian device

B.

Ability to acquire the info.mkf file on a Blackberry device and brute force the password

C.

Ability to root an Android device and perform a physical acquisition

D.

Ability to bypass the lock screen of an older iOS device

Buy Now
Question # 11

When conducting forensic analysis of an associated media card, one would most often expect to find this

particular file system format?

Options:

A.

HFS

B.

NTFS

C.

Yaffs2

D.

FAT

Buy Now
Question # 12

Using an emulator and running an application through a series of processes to figure out how it would behave on an actual device is called:

Options:

A.

Forensic analysis

B.

Dynamic analysis

C.

Web analysis

D.

Static analysis

Buy Now
Question # 13

Cellebrite Physical Analyzer uses Bit Defender to scan for malware by flagging files who have known bad hash values. This is an example of which type of mobile malware detection?

Options:

A.

Specific-based malware detection

B.

Signature-based detection

C.

Behavioral-based detection

D.

Cloud based malware detection

Buy Now
Exam Code: GASF
Exam Name: GIAC Advanced Smartphone Forensics
Last Update: Aug 24, 2025
Questions: 75
GASF pdf

GASF PDF

$25.5  $84.99
GASF Engine

GASF Testing Engine

$28.5  $94.99
GASF PDF + Engine

GASF PDF + Testing Engine

$40.5  $134.99