GIAC GASF Certification Sample Questions

GASF Dumps, GASF PDF, GASF VCE, GIAC Advanced Smartphone Forensics VCE, GIAC GASF PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Advanced Smartphone Forensics (GASF) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GASF certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GASF Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Advanced Smartphone Forensics (GASF) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Advanced Smartphone Forensics exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GASF Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GASF Sample Questions:

01. A third-party application displays, on each contact's page, a running total of items exchanged with that contact. An investigator asks the examiner to recover what that total showed on a date six weeks before seizure. The application's records hold the individual items but no stored totals.
What should the examiner report?
a) That the absence of stored totals is a negative finding establishing that the contact was not active during that period.
b) That the total for that date can be reconstructed by counting the items whose stored times fall on or before it, and reported as the value the interface showed.
c) That nothing can be reported about exchanges with that contact, since the value the interface displayed cannot be reproduced.
d) That the total is computed for display from the items held when it is drawn, so no historical value was ever stored to recover.
 
02. Static examination of an installed application package shows that the application retrieves further code from a remote server after it starts and executes it. The package's own code carries none of the behavior the complainant describes.
What does that mean for the examination?
a) The retrieved code will be recoverable in full from the handset, code that executes having to be written to storage before it can run and remaining there until the application removes it.
b) The package is not necessarily the code that ran, so the examination extends to whatever the handset retained of the retrieved code and to when each retrieval occurred.
c) The complaint is unsupported by the device, the package present on the handset being the application and containing no such behavior.
d) The retrieval routine is itself the finding, an application that fetches and runs code from a server being malicious by construction.
 
03. A colleague argues that dynamic examination of a sample in an instrumented environment is simply a more thorough version of static examination of its package, and that a dynamic run therefore makes the static work unnecessary.
Which two statements correct that view?
(Choose two.)
a) Static examination is the more thorough of the two, a package's contents being fixed while a run observes one execution.
b) They answer different questions, one about what the package contains and is built to request, the other about what the code did under the conditions the run presented.
c) The two produce the same findings by different routes, which is why either one alone is sufficient wherever the package is unpacked, readable and signed by a known party.
d) Each method is defeated by a different countermeasure: packing and obfuscation blunt the static reading, and evasion blunts the observed run.
 
04. Connection records on a seized handset show a suspect application contacting a remote endpoint repeatedly over several weeks. The investigator wants to know whether the owner's message content left the device. The examiner has a file-system extraction of that handset and nothing else.
Which two steps would materially advance that question?
(Choose two.)
a) Establish who owns the endpoint from the address held in the handset's records, and attribute the transfer to that party, to its customers, or to whoever leased the address at the time.
b) Examine the application's own storage for content staged, queued or cached for transmission, and for any record it kept of what it had sent.
c) Seek provider or network-side records covering that handset and period, under whatever separate authority those sources require.
d) Read the transmitted payloads from the handset's connection records, which retain the content alongside the endpoint address and the timestamp.
 
05. A social application's data from a seized handset yields three things: a signed-in account record, a cached copy of another user's profile image, and a message composed within the application that carries no sent indicator.
Which three statements are defensible?
(Choose three.)
a) The composed message is authored content, and nothing in it establishes that it was transmitted.
b) The composed message, read together with the account record, attributes its authorship to the handset's registered owner.
c) The cached image shows the application obtained and rendered that image, not that the user saved it.
d) The cached profile image establishes that the two account holders exchanged messages during the period the cache covers.
e) The account record shows an account was configured in the application, not who operated it.
 
06. The same application package, identical by hash, is recovered from two handsets seized from two different people in one case. Neither handset carries a record of how the package arrived.
What does the match establish?
a) That an identical build of the same application reached both handsets under examination.
b) That the two handsets were set up by the same person, an identical build being the signature of a common installer.
c) That one handset received the package from the other, an identical copy on two devices indicating a transfer between them.
d) That the match carries no evidential value on its own, hash identity across two devices being an expected consequence of ordinary application distribution and therefore uninformative about either device.
 
07. Static examination of a suspect application package finds routines that test for signs of an emulated or instrumented environment, and a routine that holds execution for an extended period after first launch.
How should the examiner treat that finding?
a) As confirmation that the application is malicious, evasion routines serving no legitimate purpose in a distributed application.
b) As an artifact introduced by the packing and obfuscation toolchain rather than a deliberate design choice, which makes it too ambiguous a signal to carry into the examination report.
c) As anti-analysis behavior that diminishes the evidential weight of a negative instrumented observation without establishing what the code performs.
d) As a reason to abandon dynamic examination and to rely on the static findings, the declared permissions and the embedded resources alone.
 
08. An examiner has searched a handset extraction for an autostart configuration of the kind a desktop examination would begin with, and found nothing of that shape. The submitting investigator asks for a finding that no persistence mechanism is present on the device.
What is the correct response?
a) Record that persistence is present but not yet located, an application of this kind necessarily surviving a restart of the device.
b) Decline it: an application persists here through platform mechanisms it registers for, among them background execution, event receivers, scheduled work and elevated administrative or assistive roles, none of which was examined.
c) Record that no persistence mechanism is present, the search having covered the boot configuration, the startup entries and the scheduled-task store a persistent application would write itself into.
d) Record that persistence would require the platform's restrictions to have been removed or bypassed, which this extraction does not show and which nothing else on the device suggests.
 
09. Inside a messaging application's own storage on a handset, an examiner finds a stored preview for a web address that appeared in a conversation: the page title, a short summary and a small image, written at the time the address was received.
What does that preview establish?
a) That the application fetched and rendered a preview of the resource when the address appeared in the conversation.
b) That no statement about the address may be made from a stored preview on its own.
c) That the handset's user opened the address in a browser, and the application recorded the visit.
d) That the resource was in the same state when it was examined as the stored title, summary and image describe it.
 
10. A handset is examined after its owner reported unexpected mobile data use. One installed application accounts for the traffic, holds a broad granted permission set, and was installed by the owner from a third-party source eight weeks earlier. The extraction shows the platform's restrictions intact and no sign that any other application's private storage has been reached.
The investigator asks the examiner to state that the device is compromised. Which reply is defensible?
a) That the device is not compromised, the application having stayed inside the boundaries the platform enforces and reached nothing beyond its own storage and its granted capabilities, which is what the security model exists to guarantee.
b) That the evidence describes this application, its granted capability and its traffic; whether the platform itself was subverted is a separate question these artifacts do not reach.
c) That the device is compromised only if the application was installed without the owner's knowledge, which the installation record here does not support.
d) That the device is compromised, an application holding that permission set having effective control of everything on it.

Answers:

Question: 01
Answer: d
Question: 02
Answer: b
Question: 03
Answer: b, d
Question: 04
Answer: b, c
Question: 05
Answer: a, c, e
Question: 06
Answer: a
Question: 07
Answer: c
Question: 08
Answer: b
Question: 09
Answer: a
Question: 10
Answer: b

Note: For any error in GIAC Advanced Smartphone Forensics (GASF) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.9 / 5 (76 votes)