- GASF Exam Overview: Format, Fees, and Logistics
- The 8 GASF Content Areas, Broken Down
- Domains 1-2: Android Application and File System Analysis
- Domains 3-4: Apple Application and File System Analysis
- Domains 5-8: Foundations, Applications, File Systems, and Malware
- How to Prioritize Study Time Across Domains
- Who Actually Tests on These Domains
- Frequently Asked Questions
- GASF covers 8 domains spanning Android, Apple, cross-platform, and malware analysis in a single 75-question exam.
- You need 69% to pass, with 2 hours to complete the exam and no electronic references allowed.
- Android and Apple domains are split into application analysis and file system artifacts-four domains total, not two.
- Registration costs $999 initially ($899 for a retake), and you have 120 days from activation to sit the exam.
GASF Exam Overview: Format, Fees, and Logistics
Before diving into content areas, it helps to understand the container they live in. The GIAC Advanced Smartphone Forensics (GASF) exam is a single, web-based, proctored assessment. You can sit it remotely through ProctorU or in person through Pearson VUE, depending on what's available in your region. There is no multi-part structure and no separate lab component - everything you need to demonstrate is compressed into one attempt.
The exam consists of 75 questions administered over two hours, and you need a score of 69% or higher to pass (this threshold applies to versions released on or after September 26, 2016). That works out to roughly 96 seconds per question on average, though in practice some questions will take far longer if they involve artifact interpretation or scenario analysis.
GIAC exams, including GASF, are open book - but only for printed materials. You can bring printed books, handwritten or printed notes, and printed indexes into the exam room or have them next to you during a remote session. Electronic devices, PDFs, and internet access are strictly prohibited during the attempt. This changes how you should prepare: building a well-organized printed index tied to each domain is far more valuable than memorizing everything cold. For a deeper walkthrough on assembling that index, see our GASF Study Guide 2026: How to Pass on Your First Attempt.
On the financial side, the initial certification attempt costs $999, with a discounted retake fee of $899 if you don't pass the first time. Once earned, the certification is valid for four years, and renewal requires 36 CPE credits along with a $499 renewal fee. For a complete cost picture including training bundles, see GASF Certification Cost 2026: Complete Pricing Breakdown.
You'll also want to plan your calendar carefully: once you activate your exam attempt, you have 120 days to sit for it. That's a hard deadline, not a suggestion - miss it and you'll need to pay again. Review scheduling logistics in GASF Exam Dates 2026: Testing Windows, Deadlines & Scheduling.
The 8 GASF Content Areas, Broken Down
GASF is structured around eight distinct domains. Unlike some certifications that blend platforms together, GASF deliberately separates Android and Apple analysis into their own application-layer and file-system-layer domains, then adds cross-platform domains that apply regardless of device manufacturer. Here's the full list as GIAC defines it:
- Domain 1: Android Device Application Analysis
- Domain 2: Android Device File System Artifacts
- Domain 3: Apple Device Application Analysis
- Domain 4: Apple Device File System Artifacts
- Domain 5: Introduction to Mobile Forensics
- Domain 6: Mobile Device Application Analysis
- Domain 7: Mobile Device File System Artifacts
- Domain 8: Mobile Device Malware Analysis
Notice the pattern: domains 1-4 are platform-specific pairs (Android app/file system, Apple app/file system), while domains 5-8 address concepts that cut across platforms - foundational methodology, general application analysis principles, general file system structures, and malware. Understanding this pairing structure helps you avoid the common mistake of treating "mobile forensics" as one undifferentiated blob of knowledge. If you want a full sense of how difficult this breadth makes the exam, read How Hard Is the GASF Exam? Complete Difficulty Guide 2026.
Domains 1-2: Android Application and File System Analysis
Domain 1: Android Device Application Analysis
This domain tests your ability to identify, extract, and interpret data generated by applications running on Android devices. You need to understand how apps store user data, cache information, and generate metadata that survives deletion or partial wiping.
- Recognizing how messaging, social media, and browser apps structure their local storage
- Interpreting SQLite database structures commonly used by Android apps
- Understanding app permission models and how they affect what forensic artifacts exist
Domain 2: Android Device File System Artifacts
Where Domain 1 focuses on application-layer data, Domain 2 pushes into the underlying file system itself - partitions, logical structures, and system-level artifacts that persist independent of any single app.
- Android partition layout and how evidence maps to specific partitions
- System logs, configuration files, and their evidentiary value
- How file system artifacts differ across Android versions and manufacturer customizations
These two domains together form a substantial share of GASF content, and candidates frequently underestimate how much low-level file system knowledge is required beyond simply knowing which app produced which artifact.
Domains 3-4: Apple Application and File System Analysis
Domain 3: Apple Device Application Analysis
This mirrors Domain 1 but for iOS. You'll need fluency in how Apple's sandboxed application model stores data, how iCloud interacts with local artifacts, and how default apps like Messages, Photos, and Health generate forensically relevant records.
- Plist file structures and how they encode application state
- Property list vs. SQLite storage patterns across common iOS apps
- Artifact differences introduced by iOS version upgrades
Domain 4: Apple Device File System Artifacts
This domain covers the iOS file system itself - directory structures, backup formats, and system-level records that exist regardless of which apps a user has installed.
- iOS backup structures and how they differ from live device extraction
- System databases that log device activity independent of specific apps
- Encryption and protection classes that affect what's recoverable
Together, the Android and Apple pairs (Domains 1-4) make platform-specific knowledge unavoidable - you cannot pass GASF by studying only one mobile ecosystem. If you're mapping out prerequisite knowledge before committing to the exam, check GASF Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Key Takeaway
Don't split your study time evenly between Android and Apple assuming symmetry. Each ecosystem has its own quirks (SQLite vs. plist conventions, partition layout vs. backup structures), so treat Domains 1-4 as four separate study blocks, not two.
Domains 5-8: Foundations, Applications, File Systems, and Malware
Domain 5: Introduction to Mobile Forensics
This is the foundational domain - terminology, acquisition methods, chain-of-custody considerations, and the general workflow examiners follow regardless of device brand. Skipping this domain because it feels "basic" is a common mistake; it establishes the vocabulary the exam uses everywhere else.
- Logical, file system, and physical acquisition method distinctions
- Legal and procedural considerations specific to mobile evidence
- General examination methodology and tool categories
Domain 6: Mobile Device Application Analysis
This domain generalizes application analysis concepts beyond any single OS - cross-platform apps, cloud-synced data, and analysis techniques that apply whether you're looking at Android or iOS.
- Cross-platform messaging and social app artifact patterns
- Cloud backup and sync implications for local evidence
- Techniques for correlating app data across multiple device types
Domain 7: Mobile Device File System Artifacts
Similar to Domain 6 but at the file system level - general principles of mobile file systems that apply across manufacturers and operating systems.
- Common file system concepts shared across mobile platforms
- Timestamp interpretation and its pitfalls across file systems
- General artifact recovery principles independent of OS
Domain 8: Mobile Device Malware Analysis
The final domain shifts from data recovery to threat analysis - identifying malicious code, understanding mobile malware behavior patterns, and recognizing indicators of compromise on smartphones.
- Common mobile malware delivery and persistence mechanisms
- Static and behavioral indicators examiners look for on compromised devices
- How malware artifacts differ from normal application behavior
Domains 5-8 test whether you can generalize beyond platform-specific memorization - a skill many candidates underdevelop when they focus too heavily on Android/Apple specifics. For a full sense of exam difficulty stemming from this breadth, our GASF Pass Rate 2026: What the Data Shows article discusses what the available data indicates about candidate performance.
How to Prioritize Study Time Across Domains
With eight domains and a 120-minute exam window, you cannot treat every domain identically in your study plan. A more efficient approach sequences domains by dependency and difficulty, building foundational knowledge before platform-specific depth.
Foundations First
- Master Domain 5 terminology and acquisition methods before anything else
- Build your printed index template for open-book reference
Android Deep Dive
- Work through Domain 1 application artifacts and Domain 2 file system structures together
- Practice interpreting SQLite outputs from common Android apps
Apple Deep Dive
- Cover Domain 3 plist and app data patterns alongside Domain 4 backup/file system structures
- Compare and contrast against Android to reinforce distinctions
Cross-Platform and Malware
- Study Domains 6 and 7 as generalization exercises across platforms
- Finish with Domain 8 malware indicators and run full practice sessions
This sequencing works because Domain 5 vocabulary appears embedded in questions across all other domains, and by studying Android and Apple in back-to-back blocks, you can directly compare their conventions rather than relearning concepts from scratch each time. For a more detailed day-by-day approach, see the GASF Study Guide 2026: How to Pass on Your First Attempt, and for a condensed reference once you're closer to test day, use the GASF Cheat Sheet 2026: One-Page Review of Must-Know Facts.
Who Actually Tests on These Domains
The eight domains aren't abstract academic categories - they map directly onto tasks performed by digital forensic examiners, incident responders, and law enforcement analysts who handle smartphone evidence regularly. Employers hiring for these roles often list GASF explicitly because it signals hands-on competency across both major mobile ecosystems plus malware triage, rather than expertise in just one platform.
If you're evaluating whether this depth of study is worth the investment, our analysis in Is the GASF Certification Worth It? Complete ROI Analysis 2026 and GASF Salary Guide 2026: Complete Earnings Analysis covers the career angle in more detail. For open roles that reference this certification directly, browse GASF Jobs.
Not sure what the credential even represents at a basic level? Start with What Is GASF?, GASF Meaning, or What Does GASF Stand For? before committing study hours to the domain content above.
| Domain Group | Domains Covered | Primary Focus |
|---|---|---|
| Android | 1, 2 | App artifacts + file system structure |
| Apple | 3, 4 | App artifacts + file system structure |
| Cross-platform foundations | 5, 6, 7 | Methodology, general app + file system principles |
| Threat analysis | 8 | Mobile malware indicators and behavior |
Frequently Asked Questions
GASF covers 8 domains: Android Device Application Analysis, Android Device File System Artifacts, Apple Device Application Analysis, Apple Device File System Artifacts, Introduction to Mobile Forensics, Mobile Device Application Analysis, Mobile Device File System Artifacts, and Mobile Device Malware Analysis.
GIAC does not publish exact per-domain weighting percentages. Since both platforms get two dedicated domains each (application and file system), candidates should prepare both ecosystems with comparable depth rather than favoring one.
Yes. GIAC exams, including GASF, are open book for printed materials only - printed books, notes, and indexes are allowed. Electronic devices and internet access are not permitted during the exam.
You need 69% overall on the 75-question exam for versions released on or after September 26, 2016. For more detail on how this threshold is applied, see GASF Passing Score 2026: Exactly What You Need to Pass.
Domain 8 focuses on recognizing mobile malware indicators and behavioral patterns as they relate to forensic examination, rather than deep binary reverse engineering. It's oriented toward examiner-level identification, not malware development analysis.