Limited-Time Summer Sale 25% Discount Offer - Apply Coupon Code: Save25
Certs Blitz
See all results for ""
Home Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
Sign in Create account
GASF EXAM PREPARATION

Prepare Smarter for the GASF Exam

Build your exam confidence with flexible preparation resources designed around the latest GASF exam objectives. Practice at your own pace using PDF questions, online exam simulations, or desktop practice software.

Download Exam View Entire Exam
Page: 1 / 2
Question #1 (Topic: Demo Questions)

Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date.

What is the name of this advanced searching capability?

A.

Watchlist Editor

B.

Tags

C.

Timeline

D.

Event of Interest

Correct Answer: C
Explanation:

Physical Analyzer offers the Timeline feature to narrow down what happened on the smartphone during a specific time, type, party, etc.

This is commonly used to narrow down time periods. Data that is manually carved will not be shown here.

There is also an option to create a custom timeline specification.

Question #2 (Topic: Demo Questions)

Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?

A.

SMS/MMS

B.

Email

C.

Call Logs

D.

Photos

Correct Answer: B
Explanation:

Photos, SMS/MMS and call logs can be extracted from a logical acquisition of a non-jailbroken device. Once a device

has been jailbroken, email can be extracted for review

Question #3 (Topic: Demo Questions)

An Android device user is known to use Facebook to communicate with other parties under examination.


There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?

A.

com.android.chrome/app_chrome/Default/Local Storage

B.

dmappmgr.db

C.

/data/system/packages.xml

D.

AndroidManifest.xml

Correct Answer: B
Explanation:

Reference:https://www.ctsforensics.com/assets/news/35550_Web-update.pdf]

Question #4 (Topic: Demo Questions)

Which file, found natively on most Android devices, will contain location history such as coordinates,

physical addresses and timestamps?

A.

/data/data/com.google.android.apps.maps/databases/da_destination_history

B.

/data/data/com.google.android.apps.maps/databases/search_history.db

C.

/data/data/com.google.android.location/files/DATA_Preferences

D.

/data/data/com.vznavigator.ADR6300/databases/NIMSTORE.db

Correct Answer: B
Explanation:

[Reference:https://books.google.com.pk/books?id=zDibrpXTfxMC&pg=PA356&lpg=PA356&dq=data/data/, com.google

.android.apps.maps/databases/da_destination_history&source=bl&ots=-KA8ikP4r&,

sig=IM_QC11zGF73P3zi8Ds9LQb2eW8&hl=en&sa=X&ved=0ahUKEwjcrObe4J7aAhXENJoKHdSLCP0,

Q6AEILzAB#v=onepage&q=data%2Fdata%2Fcom.google.android.apps.maps%2Fdatabases

%, 2Fda_destination_history&f=false]

Question #5 (Topic: Demo Questions)

Cellebrite Physical Analyzer uses Bit Defender to scan for malware by flagging files who have known bad hash values.

This is an example of which type of mobile malware detection?

A.

Specific-based malware detection

B.

Signature-based detection

C.

Behavioral-based detection

D.

Cloud based malware detection

Next Question
Correct Answer: B
Explanation:

[Reference:https://security.stackexchange.com/questions/95186/what-is-the-precise-difference-

between-asignature-based-vs-behavior-based-antiv]