Cyber Monday Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

GIAC GASF - GIAC Advanced Smartphone Forensics

Page: 2 / 3
Total 75 questions

Where are iOS Class keys stored?

A.

In iCloud

B.

Within the metadata of each file

C.

Between the flash memory and the system area on the device

D.

In effacable storage

Which of the following files contains details regarding the encryption state of an iTunes backup file?

A.

Keychain-backup.plist

B.

Manifest.mbdb

C.

Manifest.plist

D.

Status.plist

Which artifact must be carved out manually when examining a file system acquisition of an Android device?

A.

Deleted images

B.

Contacts

C.

SMS messages

D.

Phone numbers

What is the MAIN difference between a Full Root and a Shell/Soft Root?

A.

Full root is permanent

B.

Full root Leaves traces behind on the device

C.

Soft root Allows system level access without a password

D.

Soft root Utilizes Shell root

What does the data string highlighted in blue represent in the File system path?

A.

Code name and build number

B.

Phone nick name and serial number

C.

Device user name and phone number

D.

Volume name and network ID

Which artifact(s) can be extracted from a logical image only if the device the image was acquired from was jailbroken?

A.

SMS/MMS

B.

Email

C.

Call Logs

D.

Photos

An analyst is reviewing the contents of a media card that was found without an associated device. Based on the image below, with which mobile device is it most likely that this device was once paired?

A.

Android smartphone

B.

Chinese Knock-off

C.

Legacy BlackBerry

D.

Nokia device running Symbian OS

Review the two highlighted sections in the hex output below from the file MP0c_000.

Convert the phone number found in raw format extracted from a Chinese knock-off device.

A.

3494044495

B.

7034241991

C.

6174429119

D.

4349404459

Exhibit:

Where can an analyst find data to provide additional artifacts to support the evidence in the highlighted file?

A.

internal.db-wal

B.

browser2.db

C.

sysmon2.db-shm

D.

external.db

Which file, located on the Android file system, may be examined to correlate files related to external SD cards that were once used in an Android device?

A.

Internal.db

B.

Main.db

C.

DataManager. Db

D.

external.db