GIAC GASF Exam Practice Questions (P. 1)
- Full Access (71 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Based on the image below, which file system is being examined?


- AChinese knock-off
- BWindows
- CAndroid
- DBlackberry
Correct Answer:
A
Reference:
https://forums.techguy.org/threads/virus-in-china-mobile.992051/
A
Reference:
https://forums.techguy.org/threads/virus-in-china-mobile.992051/
send
light_mode
delete
Question #2
What type of acquisition is being examined in the image below?


- AiOS bypass lock
- BBlackberry logical
- CAndroid physical
- DWindows Mobile file system
Correct Answer:
C
Reference:
http://www.forensicswiki.org/wiki/How_To_Decrypt_Android_Full_Disk_Encryption
C
Reference:
http://www.forensicswiki.org/wiki/How_To_Decrypt_Android_Full_Disk_Encryption
send
light_mode
delete
Question #3
Which of the following files contains details regarding the encryption state of an iTunes backup file?
- AKeychain-backup.plist
- BManifest.mbdb
- CManifest.plist
- DStatus.plist
Correct Answer:
C
The Manifest.plist lists if the backup is encrypted. This will come into use and be required should the backup file need to be accessed forensically if it is locked. The Manifest.mbdb contains a listing of data stored in the backup. Even if the backup is encrypted, this data can be parsed for more information.
Reference:
http://resources.infosecinstitute.com/ios-5-backups-part-1/#gref
C
The Manifest.plist lists if the backup is encrypted. This will come into use and be required should the backup file need to be accessed forensically if it is locked. The Manifest.mbdb contains a listing of data stored in the backup. Even if the backup is encrypted, this data can be parsed for more information.
Reference:
http://resources.infosecinstitute.com/ios-5-backups-part-1/#gref
send
light_mode
delete
Question #4
In addition to the device passcode, what other essential piece of information is most often required in order to decrypt the contents of BlackBerry OS 10 handsets?
- ABlackBerry Blend username/pin
- BBlackBerry Balance username/password
- CBlackBerry Link ID/password
- DBBM pin
Correct Answer:
C
Special considerations when analyzing data from BlackBerry OS 10 devices:
✑ You must have the device passcode as well as the BlackBerry Link password in order to backup or view this data
✑ This requires an Internet connection on the processing machine because you are authenticating to the BlackBerry
Link Server to authenticate the username and password
✑ You may encounter issues when attempting to acquire a BES-enabled device.
C
Special considerations when analyzing data from BlackBerry OS 10 devices:
✑ You must have the device passcode as well as the BlackBerry Link password in order to backup or view this data
✑ This requires an Internet connection on the processing machine because you are authenticating to the BlackBerry
Link Server to authenticate the username and password
✑ You may encounter issues when attempting to acquire a BES-enabled device.
send
light_mode
delete
Question #5
The device pictured below is in Download Mode to attempt a physical acquisition. What can be ascertained by viewing the Android boot screen below?


- AThe Android is not rooted
- BNo ROM changes have ever occurred on this device
- CThe Original/Factory ROM is booting
- DThe Original ROM was at one time modified
Correct Answer:
C
Reference:
https://www.digitalforensics.com/blog/physical-acquisition-of-a-locked-android-device/
C
Reference:
https://www.digitalforensics.com/blog/physical-acquisition-of-a-locked-android-device/
send
light_mode
delete
All Pages