Black Friday Special Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > GIAC > Security Certification: GASF > GASF

GASF GIAC Advanced Smartphone Forensics Question and Answers

Question # 4

Which of the following is of most concern when attempting to root an Android device such as Google Glass

when conducting a forensic acquisition?

A.

Rooting this device will overwrite the data partition

B.

The manufacturer warranty is voided

C.

Device security is altered

D.

Traces of the root are left behind

Full Access
Question # 5

In 2015, Apple’s iTunes store was found to be hosting several malicious applications that were infected as a result of hacked version of the developer toolkit used to create applications. Which Apple developer suite was targeted?

A.

Xcode

B.

ADB

C.

Momentics IDE

D.

Xamarin

Full Access
Question # 6

The files pictured below from a BlackBerry OS10 file system have a unique file extension.

What can be concluded about these files?

A.

Files are protected by the file system, so changing the file system makes them less accessible

B.

Files are encrypted to prevent them from being viewed without the decryption key

C.

Files are encoded for secure transmitting of data

D.

Files are located on a media card so they contain a unique file extension

Full Access
Question # 7

While analysis in BlackBerry application list it appears that no third-party applications were installed on the device. Which other file may provide you with additional information on applications that were accessed with the handset?

A.

BlackBerry NV Items

B.

Content Store

C.

Event logs

D.

BBThumbs.dat

Full Access
Question # 8

Which of the following operating systems are used by Blackberry 10 and found in some vehicles and medical

devices?

A.

Bada

B.

POSIX

C.

QNX

D.

UNIX

Full Access
Question # 9

Exhibit:

Where can an analyst find data to provide additional artifacts to support the evidence in the highlighted file?

A.

internal.db-wal

B.

browser2.db

C.

sysmon2.db-shm

D.

external.db

Full Access
Question # 10

Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date.

What is the name of this advanced searching capability?

A.

Watchlist Editor

B.

Tags

C.

Timeline

D.

Event of Interest

Full Access
Question # 11

An analyst is investigating files on a Nokia S60 Symbian device and looking for data that would contain

possible cell tower locations, date and time stamps, phone numbers and/or references to files saved on the device. Which of the follow files would contain user data that was created and stored on the device that meet this criteria?

A.

MapView.r08

B.

LifeblogCOUNTRYSTRINGS.r1 3

C.

Lifeblog.db

D.

PbkView.r03

Full Access