10 exam-style questions with answers and explanations, straight from our 1,050-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free GASF questions are organized by exam domain, so you can see how each part of the GIAC Advanced Smartphone Forensics (GASF) blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Android Device Application Analysis
Question 1
A powered-on iPhone 15 Pro is seized during a search warrant execution. The screen is unlocked and the examiner has approximately two minutes on scene. Which action BEST preserves the greatest volume of recoverable evidence?
Show answer & explanation
Correct answer: A - Isolate it powered and unlocked inside a charging-capable Faraday bag
Question 2
An examiner has a locked iPhone 11 running current iOS, with no passcode available. A colleague suggests using checkm8 to obtain a full file system extraction. The examiner should respond that checkm8:
Show answer & explanation
Correct answer: C - Does not apply, as its scope ends at the A11 and this device runs an A13
Question 3
A cooperative suspect provides an unlocked iPhone and consents to a backup-based collection. No backup password is currently set. To maximize the data recovered, the examiner should:
Show answer & explanation
Correct answer: D - Set a known backup password on the device first, then create an encrypted backup from it
Domain 2: Android Device File System Artifacts
Question 4
An examiner exports chat.db from a full file system extraction by copying only that single file to a working directory. A commercial tool then reports 412 messages. A colleague re-parses the original extraction and reports 439. The MOST likely explanation is that the examiner's copy omitted:
Show answer & explanation
Correct answer: C - The write-ahead log, which held records not yet checkpointed into the main database file
Question 5
A SQLite field in an iOS artifact contains the value 700000000. The examiner converts it using the Unix epoch and obtains a date in 1992, which is inconsistent with the device's manufacture date. The value MOST likely represents:
Show answer & explanation
Correct answer: B - Mac Absolute Time, resolving to approximately 2023
Question 6
A tool reports that a chat database contains no recoverable deleted records. Before accepting this conclusion, the examiner should FIRST determine whether:
Show answer & explanation
Correct answer: D - The database has been vacuumed, discarding its free pages and unallocated content
Question 7
Which statement about SQLite freelist pages is accurate?
Show answer & explanation
Correct answer: A - They may retain intact record content until the engine reuses them
Domain 3: Apple Device Application Analysis
Question 8
An Android 14 device is seized in a powered-off state and booted in the lab without the user's credential. Which data is available to the examiner?
Show answer & explanation
Correct answer: C - Data in Device Encrypted storage, which remains readable before the credential is entered and serves Direct Boot-aware apps
Question 9
An examiner receives a microSD card removed from a Samsung device. The card contains data but presents no readable file system. The device itself was not seized. The MOST likely explanation is that the card:
Show answer & explanation
Correct answer: C - Was formatted as adopted storage, keyed to the device
Domain 4: Apple Device File System Artifacts
Question 10
A tool reports a device location in Hamburg at 02:14, with an accuracy value of 4200. The suspect denies ever being in Hamburg. The MOST defensible characterization of this artifact is that it:
Show answer & explanation
Correct answer: A - Places the device within a radius of several kilometres and requires corroboration