最新的GIAC Mobile Device Security Analyst - GMOB免費考試真題

問題1
Which of the following are best practices to protect data on stolen mobile devices?
(Choose two)
Response:

正確答案: A,D
問題2
In mobile application testing, what type of tool would be used to inject malicious input into an application to observe its behavior?
Response:

正確答案: D
問題3
When testing the robustness of an app's session management, what type of attack vector should be explored?
Response:

正確答案: D
問題4
In the context of SSL/TLS exploitation, what tools can be used to perform a successful Man-in-the-Middle attack?
(Choose Two)
Response:

正確答案: A,C
問題5
Which tool is commonly used for reverse engineering Android applications?
Response:

正確答案: A
問題6
What are two common techniques to mitigate against mobile malware infections?
(Choose two)
Response:

正確答案: B,D
問題7
What strategies are critical when designing an application to ensure it is resilient against malware attacks?
(Choose Two)
Response:

正確答案: B,D
問題8
How can you observe and manipulate the data traffic of an encrypted app without breaking the encryption?
Response:

正確答案: B
問題9
Which of the following are key elements to examine when performing a security assessment of Android applications?
(Choose Three)
Response:

正確答案: A,B,C
問題10
Which technologies can assist in the recovery of a stolen mobile device?
(Choose Two)
Response:

正確答案: A,C
問題11
In iOS app security testing, what file should be examined to understand the declared permissions of an app?
Response:

正確答案: D
問題12
Which vulnerability allows attackers to intercept mobile app traffic despite the use of SSL/TLS encryption?
Response:

正確答案: A
問題13
What tool is commonly used to manage Android devices in an enterprise environment?
Response:

正確答案: D
問題14
What does the OWASP MASVS framework focus on?
Response:

正確答案: A