Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

PDF GASF Study Guide

Page: 2 / 3
Total 75 questions

GIAC Advanced Smartphone Forensics Questions and Answers

Question 5

Using an emulator and running an application through a series of processes to figure out how it would behave on an actual device is called:

Options:

A.

Forensic analysis

B.

Dynamic analysis

C.

Web analysis

D.

Static analysis

Question 6

As part of your analysis of a legacy BlackBerry device, you examine the installed applications list and it

appears that no third-party applications were installed on the device. Which other file may provide you with additional information on applications that were accessed with the handset?

Options:

A.

BlackBerry NV Items

B.

Content Store

C.

Event logs

D.

BBThumbs.dat

Question 7

What does access to iOS DFU mode provide an examiner?

Options:

A.

Ability to decrypt the SD card of a Symbian device

B.

Ability to acquire the info.mkf file on a Blackberry device and brute force the password

C.

Ability to root an Android device and perform a physical acquisition

D.

Ability to bypass the lock screen of an older iOS device

Question 8

While conducting forensic analysis of an associated media card, one would most often expect to find this particular file system format?

Options:

A.

HFS

B.

NTFS

C.

Yaffs2

D.

FAT

Page: 2 / 3
Total 75 questions