
GIAC Mobile Device Security Analyst
Domain 2Objective 1
Analyzing Mobile Applications GMOB Practice Questions (Page 6)
Part of the Mobile Application Analysis and Assessment domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 26–30
- 26
You are analyzing a compiled iOS app binary and want to identify hardcoded API keys and URLs. Which tool is most appropriate for this task?
Select an answer first - 27
You need to analyze a large number of Android APKs for common insecure practices like hardcoded secrets and exported components. You want to automate the initial triage. Which tool is best suited for this?
Select an answer first - 28
You are analyzing an Android APK and notice that the AndroidManifest.xml declares an activity with the attribute `android:exported="true"` and includes an intent filter for a custom scheme. What is the primary security concern?
Select an answer first - 29
Which technique is an example of runtime manipulation?
Select an answer first - 30
What is the goal of reverse engineering a mobile application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.