Prepare Smarter for the GASF Exam
Build your exam confidence with flexible preparation resources designed around the latest GASF exam objectives. Practice at your own pace using PDF questions, online exam simulations, or desktop practice software.
Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date.
What is the name of this advanced searching capability?
Correct Answer: C
Physical Analyzer offers the Timeline feature to narrow down what happened on the smartphone during a specific time, type, party, etc.
This is commonly used to narrow down time periods. Data that is manually carved will not be shown here.
There is also an option to create a custom timeline specification.
Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?
Correct Answer: B
Photos, SMS/MMS and call logs can be extracted from a logical acquisition of a non-jailbroken device. Once a device
has been jailbroken, email can be extracted for review
An Android device user is known to use Facebook to communicate with other parties under examination.
There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?
Correct Answer: B
Reference:https://www.ctsforensics.com/assets/news/35550_Web-update.pdf]
Which file, found natively on most Android devices, will contain location history such as coordinates,
physical addresses and timestamps?
Correct Answer: B
[Reference:https://books.google.com.pk/books?id=zDibrpXTfxMC&pg=PA356&lpg=PA356&dq=data/data/, com.google
.android.apps.maps/databases/da_destination_history&source=bl&ots=-KA8ikP4r&,
sig=IM_QC11zGF73P3zi8Ds9LQb2eW8&hl=en&sa=X&ved=0ahUKEwjcrObe4J7aAhXENJoKHdSLCP0,
Q6AEILzAB#v=onepage&q=data%2Fdata%2Fcom.google.android.apps.maps%2Fdatabases
%, 2Fda_destination_history&f=false]
Cellebrite Physical Analyzer uses Bit Defender to scan for malware by flagging files who have known bad hash values.
This is an example of which type of mobile malware detection?
Correct Answer: B
[Reference:https://security.stackexchange.com/questions/95186/what-is-the-precise-difference-
between-asignature-based-vs-behavior-based-antiv]