Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Mobile Device Security Analyst

GMOBMobile Device Security Analyst

The GIAC Mobile Device Security Analyst (GMOB) certification validates your ability to assess and manage mobile device and application security, mitigate against malware and stolen devices, and analyze mobile application behavior. It is designed for security professionals, penetration testers, and auditors who protect the mobile endpoints that access critical systems. Earning GMOB demonstrates hands-on, real-world mobile security expertise that organizations rely on.

494 practice questions · Updated 2026-07-30

4Domains
11Objectives
93Concepts
494Questions

GMOB Curriculum

Every domain, objective, and concept the GMOB exam measures.

  1. Android Device Management Fundamentals
  2. Android Enterprise Deployment Models
  3. Managing Android Applications via MDM
  4. Android Application Security Controls
  5. Android Device Policy Management
  6. Android Enterprise Work Profile Management
  7. Android Device Enrollment and Provisioning
  8. Android Application Deployment Methods
  9. Android Application Configuration and Management
  10. Android Device Compliance and Monitoring

Managing iOS Devices and Applications

8 concepts · 32 questions
  1. iOS Device Enrollment
  2. Configuration Profiles
  3. App Distribution and Management
  4. iOS Security Features
  5. MDM Commands and Policies
  6. Compliance and Monitoring
  7. iOS Update Management
  8. Troubleshooting iOS Management
  1. Threat Model for Stolen Devices
  2. Remote Lock and Wipe Capabilities
  3. Device Tracking and Location Services
  4. Data Encryption and Secure Storage
  5. Authentication and Access Controls
  6. MDM Policies for Theft Mitigation
  7. Incident Response Procedures
  8. Preventive Measures and User Education

Unlocking and Rooting Mobile Devices

7 concepts · 47 questions
  1. Define unlocking and rooting
  2. Identify reasons for unlocking/rooting
  3. Describe methods of unlocking/rooting
  4. Assess security implications
  5. Evaluate organizational policies
  6. Detect unlocked/rooted devices
  7. Mitigate risks of unlocked/rooted devices

Analyzing Mobile Applications

12 concepts · 57 questions
  1. Static Analysis Fundamentals
  2. Dynamic Analysis Fundamentals
  3. Code Review Techniques
  4. Binary Analysis
  5. Manifest and Configuration Analysis
  6. Network Traffic Analysis
  7. Runtime Manipulation
  8. Memory Analysis
  9. API and Endpoint Assessment
  10. Data Storage Analysis
  11. Reverse Engineering
  12. Tool Usage and Automation

Mobile Application Security Assessments

12 concepts · 58 questions
  1. Mobile Application Security Assessment Fundamentals
  2. Threat Modeling for Mobile Apps
  3. Mobile App Architecture Analysis
  4. Static Analysis Techniques
  5. Dynamic Analysis Techniques
  6. Traffic Analysis and Interception
  7. Data Storage and Privacy Assessment
  8. Authentication and Authorization Testing
  9. Cryptography Implementation Review
  10. Platform-Specific Security Controls
  11. Reverse Engineering and Tampering Resistance
  12. Reporting and Remediation Guidance

Reverse Engineering Mobile Applications

8 concepts · 43 questions
  1. Identify reverse engineering goals
  2. Understand mobile app binary formats
  3. Use static analysis tools
  4. Perform dynamic analysis
  5. Analyze native code
  6. Bypass common protections
  7. Extract and analyze app data
  8. Document and report findings

Attacking Encrypted Traffic

9 concepts · 50 questions
  1. Encrypted Traffic Analysis
  2. TLS/SSL Protocol Fundamentals
  3. Certificate and PKI Attacks
  4. Downgrade Attacks
  5. Man-in-the-Middle (MITM) Attacks on Encrypted Traffic
  6. SSL Stripping
  7. Decryption and Key Recovery Techniques
  8. Encrypted Traffic Tunneling and Exfiltration
  9. Detection and Mitigation of Encrypted Traffic Attacks

Manipulating Network Traffic

7 concepts · 26 questions
  1. Network Traffic Capture
  2. Traffic Analysis
  3. Traffic Manipulation Techniques
  4. Proxy Configuration
  5. SSL/TLS Interception
  6. Session Management
  7. Traffic Replay and Fuzzing

  1. Identify manipulation techniques
  2. Analyze runtime manipulation
  3. Assess repackaging risks
  4. Detect tampering indicators
  5. Evaluate mitigation strategies

Mitigating Against Mobile Malware

7 concepts · 50 questions
  1. Mobile Malware Mitigation Strategies
  2. App Store Security Controls
  3. Mobile Device Management (MDM) Policies
  4. Application Sandboxing and Permissions
  5. Network Security Measures
  6. User Education and Awareness
  7. Incident Response for Mobile Malware
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GMOB, so none is invented.