- Exam Mechanics You Need to Lock In First
- The 8 GASF Domains, Ranked by Study Priority
- Android vs. Apple: Where Most Candidates Lose Points
- What GASF Questions Actually Look Like
- A GASF-Specific Study Timeline
- Building an Open-Book Index That Works Under Time Pressure
- Who Hires GASF Holders - and Why It Matters for Study Focus
- FAQ
- GASF is 75 questions in two hours, and you need 69% on exams released after September 26, 2016.
- Only printed books, notes, and tabbed indexes are allowed - no electronic materials or internet access.
- Four of the eight domains focus on Android and Apple file systems and apps; master those first.
- You get 120 days from activation to sit the exam, so register only when a date is realistic.
Exam Mechanics You Need to Lock In First
Before you open a single artifact analysis guide, you need to understand exactly what you're walking into on exam day. GASF is delivered as one web-based, proctored exam - either remotely through ProctorU or onsite via Pearson VUE. There is no lab component, no live device to image, and no simulated forensic environment. It is a knowledge exam built around 75 questions, and you have two hours to answer them, which works out to roughly 96 seconds per question if you want to leave time for review.
The passing score for versions released on or after September 26, 2016 is 69%. That number matters more than it seems - GIAC exams get revised periodically, and older prep material floating around forums may reference a different threshold. If you want the exact mechanics behind how that score is calculated and what it means for your margin of error, our GASF Passing Score 2026 breakdown walks through it question by question.
Registration isn't something to treat casually either. Once you activate your attempt, you have 120 days to sit the exam. That's generous, but it also means candidates who register before they're ready end up burning weeks of that window on procrastination. Check our GASF Exam Dates guide before you activate anything.
For a full pricing picture - including what's bundled with training versus what you pay as an exam-only candidate - see our GASF Certification Cost breakdown.
The 8 GASF Domains, Ranked by Study Priority
GASF covers eight domains, and they are not weighted equally in practice even though GIAC doesn't publish exact per-domain percentages. Based on how the material is structured, four domains form the technical core and four form the surrounding context. Here's how to think about them.
Domain 1: Android Device Application Analysis
You need to understand how Android apps store data, how permissions models affect what forensic examiners can recover, and how to interpret app-specific databases (SQLite structures, shared preferences, cache files).
- Know how third-party messaging and social apps structure their local data stores
Domain 2: Android Device File System Artifacts
This is where you master the Android partition layout, system logs, and how deleted or fragmented data persists in unallocated space on Android file systems.
- Be fluent in identifying artifacts across YAFFS2, EXT4, and F2FS variations
Domain 3: Apple Device Application Analysis
Apple's sandboxing model changes the game compared to Android. Focus on how iOS apps isolate data, how backups expose app content, and how to interpret plist files.
- Understand the relationship between app containers and iTunes/Finder backup structures
Domain 4: Apple Device File System Artifacts
This domain demands fluency in HFS+/APFS structures, keychain analysis, and how iOS logs system-level events that survive app deletion.
- Practice tracing timestamps across multiple Apple-native databases
Together, Domains 1-4 make up half the certification's content areas and represent the platform-specific depth that separates GASF from a general digital forensics credential. If you want the complete walkthrough of all eight areas with more granular subtopics, read our GASF Exam Domains 2026 guide.
Domain 5: Introduction to Mobile Forensics
This sets the foundation - acquisition methods, chain of custody considerations specific to mobile devices, and the legal/technical constraints of extracting data from a locked or damaged phone.
- Know the difference between physical, file system, and logical extraction methods
Domain 6: Mobile Device Application Analysis
A cross-platform domain testing whether you can analyze app behavior independent of OS specifics - think cloud sync artifacts, app metadata, and cross-referencing timestamps between apps.
- Practice correlating activity across multiple apps on the same device
Domain 7: Mobile Device File System Artifacts
This domain tests general file system concepts that apply regardless of manufacturer - journaling, metadata structures, and how deleted data behaves across mobile storage types.
- Be comfortable explaining artifact persistence without platform-specific tools
Domain 8: Mobile Device Malware Analysis
Often underestimated. You need to recognize indicators of mobile malware, spyware, and stalkerware - including persistence mechanisms and how malicious apps disguise their file system footprint.
- Study known mobile malware families and their typical artifact signatures
Android vs. Apple: Where Most Candidates Lose Points
Candidates who come from an Apple-heavy forensic background tend to underestimate Android's fragmentation - file system variants, manufacturer skins, and inconsistent logging make Domain 2 harder to generalize than Domain 4. Conversely, candidates strong in Android often underestimate how much of Apple's ecosystem (Domains 3 and 4) hinges on understanding backup structures and keychain encryption rather than raw file system parsing.
| Area | Android Focus | Apple Focus |
|---|---|---|
| File System | EXT4/F2FS variants, fragmentation across OEMs | APFS/HFS+, more consistent structure |
| App Data | SQLite, shared preferences, permission model | Sandboxed containers, plist files |
| Backups | OEM-dependent, cloud-variable | iTunes/Finder and iCloud backup consistency |
| Common Pitfall | Assuming uniform behavior across manufacturers | Overlooking encryption layers in keychain data |
This split is exactly why the exam devotes four separate domains to platform-specific analysis instead of lumping "mobile forensics" into one bucket. If you're still deciding how much time this level of depth actually requires, our How Hard Is the GASF Exam guide puts the platform-specific workload in context against other GIAC certifications.
What GASF Questions Actually Look Like
GASF questions are scenario-driven rather than pure definition recall. Expect to be given a short forensic scenario - a device type, an extraction method already performed, and a specific artifact or log excerpt - and asked to identify what it indicates or what step comes next. This format rewards candidates who've actually practiced reading raw artifact output, not just memorized terminology.
- Multiple-choice format, single best answer
- Scenario framing common in application analysis and malware domains
- Occasional questions referencing specific file paths or database table names
- No simulation or hands-on lab component within the exam itself
Key Takeaway
Practice reading actual artifact excerpts - plist snippets, SQLite table structures, log fragments - rather than relying only on textbook definitions. The exam tests interpretation, not vocabulary.
A GASF-Specific Study Timeline
Generic study frameworks don't map well onto a certification this platform-specific. Instead, sequence your preparation around the domain clusters described above, moving from foundational concepts to platform depth to cross-platform synthesis.
Foundations
- Work through Domain 5 (Introduction to Mobile Forensics) and acquisition methodology
- Build the skeleton of your open-book index
Android Depth
- Cover Domains 1 and 2 together - application analysis and file system artifacts reinforce each other
Apple Depth
- Cover Domains 3 and 4, focusing on backup structures and keychain/plist interpretation
Cross-Platform and Malware
- Study Domains 6, 7, and 8 together, since they test generalized concepts across both platforms
- Run full-length practice questions under timed conditions
Notice this timeline deliberately avoids generic techniques like blanket flashcard drilling across all domains simultaneously - GASF rewards sequencing by platform because so much of the terminology and artifact logic is shared within, but not between, Android and Apple domains. For a broader framework, our flagship GASF Study Guide 2026 covers additional pacing options.
Building an Open-Book Index That Works Under Time Pressure
GIAC's open-book policy is one of the most distinctive features of this exam, and also one of the most misunderstood. You're allowed printed books, printed notes, and a printed index - but electronic materials and internet access are strictly prohibited. That means your index has to work as a physical lookup tool you can navigate in under 30 seconds per query, because your two-hour window doesn't forgive slow searching.
- Organize your index by domain, not alphabetically by term - you'll usually know which domain a question is testing before you know the exact keyword
- Include page references for specific artifact tables, plist structures, and file path examples
- Tab your printed materials physically; don't rely solely on the index document
- Test your index against timed practice questions before exam day, not during it
For a condensed reference you can build your own index around, our GASF Cheat Sheet 2026 summarizes the must-know facts in one page.
Who Hires GASF Holders - and Why It Matters for Study Focus
GASF sits squarely in the digital forensics and incident response space, and it's typically pursued by examiners who already handle mobile evidence in law enforcement, corporate investigations, or eDiscovery contexts. Employers looking for this credential are generally validating that a candidate can move beyond general computer forensics into the specific challenges mobile devices present - encrypted containers, app-specific data stores, and rapidly changing OS versions.
Because the certification is so platform-specific, candidates who already work mobile cases day-to-day tend to find the domain balance intuitive, while those coming from traditional disk forensics backgrounds need to invest more time in Domains 1-4. If you're weighing whether this specialization fits your career path, our GASF Jobs overview and GASF Salary Guide 2026 lay out where this credential tends to show up in job postings and how it factors into compensation conversations. For a broader ROI view before you commit to the $999 attempt fee, Is the GASF Certification Worth It? is worth reading first.
If you're still confirming eligibility or figuring out whether prerequisite experience is expected, our GASF Requirements guide clarifies what GIAC actually requires versus what's simply recommended.
Key Takeaway
Renewal requires 36 CPE credits within the four-year validity period and a $499 renewal fee - factor ongoing mobile OS updates into your CPE plan since platforms change annually.
Once you're confident in your domain-by-domain readiness, running full-length timed drills through our GASF practice test platform is the best way to confirm your pacing matches the real 75-question, two-hour format. It's also the fastest way to identify which of the eight domains still needs another pass before you spend $999 on an attempt. Many candidates use our practice questions specifically to stress-test their open-book index under realistic time constraints before committing to a registration date.
FAQ
The exam has 75 questions to be completed within two hours, delivered as a proctored, web-based test through ProctorU or Pearson VUE.
For exam versions released on or after September 26, 2016, you need 69% to pass. Check our GASF Passing Score guide for details on how this applies to current versions.
No. GIAC exams are open book for printed books, printed notes, and printed indexes only. Electronic materials and internet access are strictly prohibited during the exam.
A first attempt costs $999, while a retake is priced at $899. Because the difference is small, thorough first-attempt preparation is far more cost-effective than planning to retake.
You have 120 days from activation to complete your exam attempt, so it's best to activate only once you have a realistic study and scheduling plan in place.