GIAC GASF Exam Practice Questions (P. 4)
- Full Access (71 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
Where can an analyst find data to provide additional artifacts to support the evidence in the highlighted file?


send
light_mode
delete
Question #17
Which of the following is a unique 56 bit number assigned to a CDMA handset?
- AMobile Station International Subscriber Directory Number (MSISDN)
- BElectronic Serial Number (ESN)
- CInternational Mobile Equipment Identifier (IMEI)
- DMobile Equipment ID (MEID)
Correct Answer:
D
The Mobile Equipment ID (MEID), also found under the battery cover, is a 56 bit number which replaced the ESN due to the limited number of 32 bit
ESN numbers. The MEID is listed in hex, where the first byte is a regional code, next three bytes are a manufacturer code, and remaining three bytes are a manufacturer-assigned serial number.
Reference:
https://sites.google.com/site/bbayles/index/cdma_hardware_id
D
The Mobile Equipment ID (MEID), also found under the battery cover, is a 56 bit number which replaced the ESN due to the limited number of 32 bit
ESN numbers. The MEID is listed in hex, where the first byte is a regional code, next three bytes are a manufacturer code, and remaining three bytes are a manufacturer-assigned serial number.
Reference:
https://sites.google.com/site/bbayles/index/cdma_hardware_id
send
light_mode
delete
Question #18
Which of the following files provides the most accurate reflection of the device’s date/timestamp related to the last device wipe?
- A/private/var/mobile/Library/AddressBook/AddressBook.sqlitedb
- B/private/var/mobile/Applications/com.apple.mobilesafari/Library/history.db
- C/private/var/mobile/Applications/com.viber/Library/Prefernces/com.viber.plist
- D/private/var/mobile/Applications/net.whatsapp.WhatsApp/Library/pw.dat
Correct Answer:
A
A
send
light_mode
delete
Question #19
Which of the following is the term for the SMS malware that sends text messages to a premium number generating large service bills for the user of the targeted device?
- ATrojan
- BAdware
- CPotentially unwanted applications
- DClick bait
Correct Answer:
A
Reference:
https://pdfs.semanticscholar.org/7f33/9156f47345bd102c9b05f45f9bfe4c182720.pdf
A
Reference:
https://pdfs.semanticscholar.org/7f33/9156f47345bd102c9b05f45f9bfe4c182720.pdf
send
light_mode
delete
Question #20
When examining the iOS device shown below the tool indicates that there are 4 chat messages recovered from the device. Which of the following locations may contain additional chat information?


- AMemory ranges from a physical dump of the device
- BDatabases installed and maintained by the application
- CInternet history plist files found in logical acquisitions
- DIP connections used by the application
Correct Answer:
B
B
send
light_mode
delete
All Pages
