
GIAC Mobile Device Security Analyst
The GIAC Mobile Device Security Analyst (GMOB) certification validates your ability to assess and manage mobile device and application security, mitigate against malware and stolen devices, and analyze mobile application behavior. It is designed for security professionals, penetration testers, and auditors who protect the mobile endpoints that access critical systems. Earning GMOB demonstrates hands-on, real-world mobile security expertise that organizations rely on.
494 practice questions · Updated 2026-07-30
4Domains
11Objectives
93Concepts
494Questions
GMOB Curriculum
Every domain, objective, and concept the GMOB exam measures.
- Android Device Management Fundamentals
- Android Enterprise Deployment Models
- Managing Android Applications via MDM
- Android Application Security Controls
- Android Device Policy Management
- Android Enterprise Work Profile Management
- Android Device Enrollment and Provisioning
- Android Application Deployment Methods
- Android Application Configuration and Management
- Android Device Compliance and Monitoring
- iOS Device Enrollment
- Configuration Profiles
- App Distribution and Management
- iOS Security Features
- MDM Commands and Policies
- Compliance and Monitoring
- iOS Update Management
- Troubleshooting iOS Management
- Threat Model for Stolen Devices
- Remote Lock and Wipe Capabilities
- Device Tracking and Location Services
- Data Encryption and Secure Storage
- Authentication and Access Controls
- MDM Policies for Theft Mitigation
- Incident Response Procedures
- Preventive Measures and User Education
- Define unlocking and rooting
- Identify reasons for unlocking/rooting
- Describe methods of unlocking/rooting
- Assess security implications
- Evaluate organizational policies
- Detect unlocked/rooted devices
- Mitigate risks of unlocked/rooted devices
- Static Analysis Fundamentals
- Dynamic Analysis Fundamentals
- Code Review Techniques
- Binary Analysis
- Manifest and Configuration Analysis
- Network Traffic Analysis
- Runtime Manipulation
- Memory Analysis
- API and Endpoint Assessment
- Data Storage Analysis
- Reverse Engineering
- Tool Usage and Automation
- Mobile Application Security Assessment Fundamentals
- Threat Modeling for Mobile Apps
- Mobile App Architecture Analysis
- Static Analysis Techniques
- Dynamic Analysis Techniques
- Traffic Analysis and Interception
- Data Storage and Privacy Assessment
- Authentication and Authorization Testing
- Cryptography Implementation Review
- Platform-Specific Security Controls
- Reverse Engineering and Tampering Resistance
- Reporting and Remediation Guidance
- Identify reverse engineering goals
- Understand mobile app binary formats
- Use static analysis tools
- Perform dynamic analysis
- Analyze native code
- Bypass common protections
- Extract and analyze app data
- Document and report findings
- Encrypted Traffic Analysis
- TLS/SSL Protocol Fundamentals
- Certificate and PKI Attacks
- Downgrade Attacks
- Man-in-the-Middle (MITM) Attacks on Encrypted Traffic
- SSL Stripping
- Decryption and Key Recovery Techniques
- Encrypted Traffic Tunneling and Exfiltration
- Detection and Mitigation of Encrypted Traffic Attacks
- Network Traffic Capture
- Traffic Analysis
- Traffic Manipulation Techniques
- Proxy Configuration
- SSL/TLS Interception
- Session Management
- Traffic Replay and Fuzzing
- Identify manipulation techniques
- Analyze runtime manipulation
- Assess repackaging risks
- Detect tampering indicators
- Evaluate mitigation strategies
- Mobile Malware Mitigation Strategies
- App Store Security Controls
- Mobile Device Management (MDM) Policies
- Application Sandboxing and Permissions
- Network Security Measures
- User Education and Awareness
- Incident Response for Mobile Malware
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GMOB, so none is invented.