GIAC GASF Exam Practice Questions (P. 3)
- Full Access (71 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
Which of the following is required in addition to the Apple ID of the custodian to access IOS backup files that are stored in ICloud?
- AiTunes password
- BDevice passcode
- CManifest.plist
- DKeychain-backup.plist
Correct Answer:
B
B
send
light_mode
delete
Question #12
In 2015, Apples iTunes store was found to be hosting several malicious applications that were infected as a result of hacked version of the developer toolkit used to create applications. Which Apple developer suite was targeted?
- AXcode
- BADB
- CMomentics IDE
- DXamarin
Correct Answer:
A
Reference:
http://money.cnn.com/2015/09/21/technology/apple-xcode-hack/index.html
A
Reference:
http://money.cnn.com/2015/09/21/technology/apple-xcode-hack/index.html
send
light_mode
delete
Question #13
An Android device user is known to use Facebook to communicate with other parties under examination. There is no evidence of the Facebook application on the phone. If there was Facebook usage where would an examiner expect to find these artifacts?
- Acom.android.chrome/app_chrome/Default/Local Storage
- Bdmappmgr.db
- C/data/system/packages.xml
- DAndroidManifest.xml
Correct Answer:
B
Reference:
https://www.ctsforensics.com/assets/news/35550_Web-update.pdf
B
Reference:
https://www.ctsforensics.com/assets/news/35550_Web-update.pdf
send
light_mode
delete
Question #14
Physical Analyzer provides a function to narrow down a search based on a timestamp, a type, a party or date. What is the name of this advanced searching capability?
- AWatchlist Editor
- BTags
- CTimeline
- DEvent of Interest
Correct Answer:
C
Physical Analyzer offers the Timeline feature to narrow down what happened on the smartphone during a specific time, type, party, etc. This is commonly used to narrow down time periods. Data that is manually carved will not be shown here. There is also an option to create a custom timeline specification.
C
Physical Analyzer offers the Timeline feature to narrow down what happened on the smartphone during a specific time, type, party, etc. This is commonly used to narrow down time periods. Data that is manually carved will not be shown here. There is also an option to create a custom timeline specification.
send
light_mode
delete
Question #15
The files pictured below from a BlackBerry OS10 file system have a unique file extension. What can be concluded about these files?


- AFiles are protected by the file system, so changing the file system makes them less accessible
- BFiles are encrypted to prevent them from being viewed without the decryption key
- CFiles are encoded for secure transmitting of data
- DFiles are located on a media card so they contain a unique file extension
Correct Answer:
A
Reference:
https://forums.crackberry.com/blackberry-q10-f272/protected-media-911023/
A
Reference:
https://forums.crackberry.com/blackberry-q10-f272/protected-media-911023/
send
light_mode
delete
All Pages