GASF logo
Focused certification exam prep
Start practice

GASF Exam Domains 2026: Complete Guide to All 8 Content Areas

TL;DR
  • GASF covers 8 domains spanning Android, Apple, cross-platform, and malware analysis in a single 75-question exam.
  • You need 69% to pass, with 2 hours to complete the exam and no electronic references allowed.
  • Android and Apple domains are split into application analysis and file system artifacts-four domains total, not two.
  • Registration costs $999 initially ($899 for a retake), and you have 120 days from activation to sit the exam.

GASF Exam Overview: Format, Fees, and Logistics

Before diving into content areas, it helps to understand the container they live in. The GIAC Advanced Smartphone Forensics (GASF) exam is a single, web-based, proctored assessment. You can sit it remotely through ProctorU or in person through Pearson VUE, depending on what's available in your region. There is no multi-part structure and no separate lab component - everything you need to demonstrate is compressed into one attempt.

The exam consists of 75 questions administered over two hours, and you need a score of 69% or higher to pass (this threshold applies to versions released on or after September 26, 2016). That works out to roughly 96 seconds per question on average, though in practice some questions will take far longer if they involve artifact interpretation or scenario analysis.

GIAC exams, including GASF, are open book - but only for printed materials. You can bring printed books, handwritten or printed notes, and printed indexes into the exam room or have them next to you during a remote session. Electronic devices, PDFs, and internet access are strictly prohibited during the attempt. This changes how you should prepare: building a well-organized printed index tied to each domain is far more valuable than memorizing everything cold. For a deeper walkthrough on assembling that index, see our GASF Study Guide 2026: How to Pass on Your First Attempt.

On the financial side, the initial certification attempt costs $999, with a discounted retake fee of $899 if you don't pass the first time. Once earned, the certification is valid for four years, and renewal requires 36 CPE credits along with a $499 renewal fee. For a complete cost picture including training bundles, see GASF Certification Cost 2026: Complete Pricing Breakdown.

You'll also want to plan your calendar carefully: once you activate your exam attempt, you have 120 days to sit for it. That's a hard deadline, not a suggestion - miss it and you'll need to pay again. Review scheduling logistics in GASF Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Format Snapshot: 75 questions, 120 minutes, 69% to pass, open-book with printed materials only, $999 to register, 120 days to test after activation. These numbers should anchor every study plan you build.

The 8 GASF Content Areas, Broken Down

GASF is structured around eight distinct domains. Unlike some certifications that blend platforms together, GASF deliberately separates Android and Apple analysis into their own application-layer and file-system-layer domains, then adds cross-platform domains that apply regardless of device manufacturer. Here's the full list as GIAC defines it:

  • Domain 1: Android Device Application Analysis
  • Domain 2: Android Device File System Artifacts
  • Domain 3: Apple Device Application Analysis
  • Domain 4: Apple Device File System Artifacts
  • Domain 5: Introduction to Mobile Forensics
  • Domain 6: Mobile Device Application Analysis
  • Domain 7: Mobile Device File System Artifacts
  • Domain 8: Mobile Device Malware Analysis

Notice the pattern: domains 1-4 are platform-specific pairs (Android app/file system, Apple app/file system), while domains 5-8 address concepts that cut across platforms - foundational methodology, general application analysis principles, general file system structures, and malware. Understanding this pairing structure helps you avoid the common mistake of treating "mobile forensics" as one undifferentiated blob of knowledge. If you want a full sense of how difficult this breadth makes the exam, read How Hard Is the GASF Exam? Complete Difficulty Guide 2026.

Domains 1-2: Android Application and File System Analysis

Domain 1: Android Device Application Analysis

This domain tests your ability to identify, extract, and interpret data generated by applications running on Android devices. You need to understand how apps store user data, cache information, and generate metadata that survives deletion or partial wiping.

  • Recognizing how messaging, social media, and browser apps structure their local storage
  • Interpreting SQLite database structures commonly used by Android apps
  • Understanding app permission models and how they affect what forensic artifacts exist

Domain 2: Android Device File System Artifacts

Where Domain 1 focuses on application-layer data, Domain 2 pushes into the underlying file system itself - partitions, logical structures, and system-level artifacts that persist independent of any single app.

  • Android partition layout and how evidence maps to specific partitions
  • System logs, configuration files, and their evidentiary value
  • How file system artifacts differ across Android versions and manufacturer customizations

These two domains together form a substantial share of GASF content, and candidates frequently underestimate how much low-level file system knowledge is required beyond simply knowing which app produced which artifact.

Domains 3-4: Apple Application and File System Analysis

Domain 3: Apple Device Application Analysis

This mirrors Domain 1 but for iOS. You'll need fluency in how Apple's sandboxed application model stores data, how iCloud interacts with local artifacts, and how default apps like Messages, Photos, and Health generate forensically relevant records.

  • Plist file structures and how they encode application state
  • Property list vs. SQLite storage patterns across common iOS apps
  • Artifact differences introduced by iOS version upgrades

Domain 4: Apple Device File System Artifacts

This domain covers the iOS file system itself - directory structures, backup formats, and system-level records that exist regardless of which apps a user has installed.

  • iOS backup structures and how they differ from live device extraction
  • System databases that log device activity independent of specific apps
  • Encryption and protection classes that affect what's recoverable

Together, the Android and Apple pairs (Domains 1-4) make platform-specific knowledge unavoidable - you cannot pass GASF by studying only one mobile ecosystem. If you're mapping out prerequisite knowledge before committing to the exam, check GASF Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Key Takeaway

Don't split your study time evenly between Android and Apple assuming symmetry. Each ecosystem has its own quirks (SQLite vs. plist conventions, partition layout vs. backup structures), so treat Domains 1-4 as four separate study blocks, not two.

Domains 5-8: Foundations, Applications, File Systems, and Malware

Domain 5: Introduction to Mobile Forensics

This is the foundational domain - terminology, acquisition methods, chain-of-custody considerations, and the general workflow examiners follow regardless of device brand. Skipping this domain because it feels "basic" is a common mistake; it establishes the vocabulary the exam uses everywhere else.

  • Logical, file system, and physical acquisition method distinctions
  • Legal and procedural considerations specific to mobile evidence
  • General examination methodology and tool categories

Domain 6: Mobile Device Application Analysis

This domain generalizes application analysis concepts beyond any single OS - cross-platform apps, cloud-synced data, and analysis techniques that apply whether you're looking at Android or iOS.

  • Cross-platform messaging and social app artifact patterns
  • Cloud backup and sync implications for local evidence
  • Techniques for correlating app data across multiple device types

Domain 7: Mobile Device File System Artifacts

Similar to Domain 6 but at the file system level - general principles of mobile file systems that apply across manufacturers and operating systems.

  • Common file system concepts shared across mobile platforms
  • Timestamp interpretation and its pitfalls across file systems
  • General artifact recovery principles independent of OS

Domain 8: Mobile Device Malware Analysis

The final domain shifts from data recovery to threat analysis - identifying malicious code, understanding mobile malware behavior patterns, and recognizing indicators of compromise on smartphones.

  • Common mobile malware delivery and persistence mechanisms
  • Static and behavioral indicators examiners look for on compromised devices
  • How malware artifacts differ from normal application behavior

Domains 5-8 test whether you can generalize beyond platform-specific memorization - a skill many candidates underdevelop when they focus too heavily on Android/Apple specifics. For a full sense of exam difficulty stemming from this breadth, our GASF Pass Rate 2026: What the Data Shows article discusses what the available data indicates about candidate performance.

How to Prioritize Study Time Across Domains

With eight domains and a 120-minute exam window, you cannot treat every domain identically in your study plan. A more efficient approach sequences domains by dependency and difficulty, building foundational knowledge before platform-specific depth.

Week 1

Foundations First

  • Master Domain 5 terminology and acquisition methods before anything else
  • Build your printed index template for open-book reference
Week 2

Android Deep Dive

  • Work through Domain 1 application artifacts and Domain 2 file system structures together
  • Practice interpreting SQLite outputs from common Android apps
Week 3

Apple Deep Dive

  • Cover Domain 3 plist and app data patterns alongside Domain 4 backup/file system structures
  • Compare and contrast against Android to reinforce distinctions
Week 4

Cross-Platform and Malware

  • Study Domains 6 and 7 as generalization exercises across platforms
  • Finish with Domain 8 malware indicators and run full practice sessions

This sequencing works because Domain 5 vocabulary appears embedded in questions across all other domains, and by studying Android and Apple in back-to-back blocks, you can directly compare their conventions rather than relearning concepts from scratch each time. For a more detailed day-by-day approach, see the GASF Study Guide 2026: How to Pass on Your First Attempt, and for a condensed reference once you're closer to test day, use the GASF Cheat Sheet 2026: One-Page Review of Must-Know Facts.

Who Actually Tests on These Domains

The eight domains aren't abstract academic categories - they map directly onto tasks performed by digital forensic examiners, incident responders, and law enforcement analysts who handle smartphone evidence regularly. Employers hiring for these roles often list GASF explicitly because it signals hands-on competency across both major mobile ecosystems plus malware triage, rather than expertise in just one platform.

If you're evaluating whether this depth of study is worth the investment, our analysis in Is the GASF Certification Worth It? Complete ROI Analysis 2026 and GASF Salary Guide 2026: Complete Earnings Analysis covers the career angle in more detail. For open roles that reference this certification directly, browse GASF Jobs.

Not sure what the credential even represents at a basic level? Start with What Is GASF?, GASF Meaning, or What Does GASF Stand For? before committing study hours to the domain content above.

Domain GroupDomains CoveredPrimary Focus
Android1, 2App artifacts + file system structure
Apple3, 4App artifacts + file system structure
Cross-platform foundations5, 6, 7Methodology, general app + file system principles
Threat analysis8Mobile malware indicators and behavior
Practice Under Real Conditions: Since GASF is open-book only for printed materials and gives you just two hours for 75 questions, rehearsing with timed, domain-tagged practice questions on our practice test platform is one of the most direct ways to simulate exam-day pressure before you sit the real thing.

Frequently Asked Questions

How many domains does the GASF exam cover?

GASF covers 8 domains: Android Device Application Analysis, Android Device File System Artifacts, Apple Device Application Analysis, Apple Device File System Artifacts, Introduction to Mobile Forensics, Mobile Device Application Analysis, Mobile Device File System Artifacts, and Mobile Device Malware Analysis.

Are Android and Apple domains weighted equally on the exam?

GIAC does not publish exact per-domain weighting percentages. Since both platforms get two dedicated domains each (application and file system), candidates should prepare both ecosystems with comparable depth rather than favoring one.

Can I bring notes into the GASF exam to help with the domains?

Yes. GIAC exams, including GASF, are open book for printed materials only - printed books, notes, and indexes are allowed. Electronic devices and internet access are not permitted during the exam.

What score do I need across these domains to pass GASF?

You need 69% overall on the 75-question exam for versions released on or after September 26, 2016. For more detail on how this threshold is applied, see GASF Passing Score 2026: Exactly What You Need to Pass.

Does the GASF malware domain require malware reverse engineering skills?

Domain 8 focuses on recognizing mobile malware indicators and behavioral patterns as they relate to forensic examination, rather than deep binary reverse engineering. It's oriented toward examiner-level identification, not malware development analysis.

Ready to pass your GASF exam?

Put this into practice with free GASF questions across every exam domain.