GIAC · Advanced Smartphone Forensics GASF

GIAC Advanced Smartphone Forensics GASF Exam Practice Questions

71 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 71 questions in this pack

Question 1

Based on the image below, which file system is being examined?

Exhibit for question 1

  1. Chinese knock-off
  2. Windows
  3. Android
  4. Blackberry
Show answer and explanation

Correct answer: C. Android

The file system structure shown contains characteristic Android directories and files including NVRAM, NVD_DATA, @WAP, @BPP, @FTP, @USER, @WCACHE, and @BT folders, along with files like DEVDB. The presence of MMS, Photos, Download, and Ebook folders organized in this hierarchical manner is typical of Android file systems. The naming conventions (using @ prefixes for system directories) and the overall structure match Android's internal storage organization rather than other mobile operating systems.

Why the other options are wrong

  • A. Chinese knock-off phones would typically use modified versions of Android or Windows rather than a distinct proprietary file system with these specific directory structures.
  • B. Windows file systems use different directory structures like Windows, System32, Program Files, and Users; the directory names shown are not characteristic of Windows.
  • D. BlackBerry devices used proprietary file systems with different organization patterns and would not show this mix of Android-specific directories like NVRAM and @WAP.

Question 2

What type of acquisition is being examined in the image below?

Exhibit for question 2

  1. iOS bypass lock
  2. Blackberry logical
  3. Android physical
  4. Windows Mobile file system
Show answer and explanation

Correct answer: C. Android physical

The GIAC TEST - Autopsy 3.1.3 interface shown displays a physical acquisition of a mobile device's file system. The evidence includes multiple volumes (vol1-vol13) with various partitions including BOOT, BOTAO, BOOTA1, EFS, PARAM, RECOVERY, RADIO, CACHE, SYSTEM, and HIDDEN - a characteristic partition structure of Android devices. The volumes show starting sectors and length measurements in sectors, indicating raw physical disk imaging rather than logical extraction or file-level acquisition. The presence of Android-specific partitions like RECOVERY, RADIO, and CACHE, combined with the sector-level analysis shown in Autopsy, confirms this is a physical acquisition of an Android device's file system.

Why the other options are wrong

  • A. iOS bypass lock examinations involve different tools and would not show Android- specific partitions like RADIO, RECOVERY, and CACHE.
  • B. Blackberry logical acquisitions extract logical files and data at a higher level, not raw sector-level partitions with boot sectors and system partitions as shown here.
  • D. Windows Mobile file system acquisitions would display Windows Mobile-specific partitions and file structures, not the Android partition scheme visible in this image.

Question 3

Which of the following files contains details regarding the encryption state of an iTunes backup file?

  1. Keychain-backup.plist
  2. Manifest.mbdb
  3. Manifest.plist
  4. Status.plist
Show answer and explanation

Correct answer: C. Manifest.plist

The Manifest.plist file contains metadata about an iTunes backup, including encryption state information. This file is a property list that stores backup configuration details and encryption status flags that indicate whether the backup is encrypted or not.

Why the other options are wrong

  • A. Keychain-backup.plist stores encrypted keychain data but does not contain overall backup encryption state metadata.
  • B. Manifest.mbdb is a binary database file containing file metadata and checksums but not encryption state information.
  • D. Status.plist is not a standard iTunes backup file that tracks encryption state.

See all 10 free questions Get the full pack, US$39

71 practice questions for GIAC Advanced Smartphone Forensics (GASF) certification, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 71 questions mapped to the GASF exam certification objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A GASF attempt costs US$999 (US$899 for a retake). This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 71 questions

What makes the GASF hard

GASF is the GIAC certification paired with the SANS FOR585 smartphone forensics course, and like every GIAC exam it is open book: hardcopy books and personal notes are allowed, the internet and electronic files are not. That changes how candidates prepare.

The exam is 75 questions in two hours with a 69% pass mark, which leaves about 96 seconds a question, so a good index into notes matters more than memorising, and the questions are written so that looking everything up will run out the clock.

The objectives follow a phone from acquisition to report: mobile forensics fundamentals and acquisition methods, Android and iOS file system and artefact analysis, third-party application analysis, malware and spyware detection, event and location artefact analysis, and cloud-stored data and tool validation. Questions frequently show a table, hex or a database row and ask what it means, so recognising artefact structures on sight is what passes this exam.

About the exam

GASF (GIAC Advanced Smartphone Forensics) validates forensic examination of mobile phones and tablets: mobile forensics fundamentals, Android and iOS file system and artefact analysis, application analysis, malware and spyware detection, event artefact analysis, and reporting. There are no prerequisites; it is aligned to SANS FOR585.

Exam certification objectives

  • Mobile forensics fundamentals and acquisition
  • Android file system and artefact analysis
  • iOS file system and artefact analysis
  • Third-party application and database analysis
  • Malware and spyware detection
  • Event, location and timeline artefact analysis
  • Backups, cloud data and tool validation

GIAC does not publish weightings. 75 questions, 120 minutes, open book (hardcopy only), passing score 69%, US$999 per attempt, ProctorU remote or Pearson VUE test centre, certification valid for four years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Advanced Smartphone Forensics GASF pack?

71 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.