Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Mobile Device Security Analyst

Domain 3Objective 1

Attacking Encrypted Traffic GMOB Practice Questions (Page 2)

Part of the Network Traffic Manipulation and Security domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
9concepts

Questions 6–10

  1. 6application · medium

    A security analyst is monitoring network traffic and notices a mobile device is communicating with a known command-and-control server using TLS on port 443. The traffic pattern is unusual: the packets are small, regular, and occur at the same time every day. Which of the following is the most appropriate next step?

    Select an answer first
  2. 7application · medium

    A security team is investigating a mobile app that uses certificate pinning. They discover that the app is vulnerable to a man-in-the-middle attack because it does not validate the certificate chain correctly. Which attack would be most directly enabled by this vulnerability?

    Select an answer first
  3. 8application · medium

    A security analyst is investigating a report that users on the corporate Wi-Fi network see a browser warning when visiting a popular news site. The analyst captures traffic and notices that the site's HTTPS requests are being redirected to HTTP on port 80, and the HTTP responses contain a 302 redirect back to HTTPS. However, some users still see the warning. Which technique is most likely being used, and what is the primary reason the warning appears?

    Select an answer first
  4. 9foundation · easy

    Which of the following is a technique used to detect malicious activity in encrypted traffic without decrypting it?

    Select an answer first
  5. 10application · medium

    A security analyst is reviewing a packet capture of a mobile device's TLS traffic. The capture shows a ClientHello with TLS 1.2 and a cipher suite of TLS_RSA_WITH_AES_128_CBC_SHA. The server responds with a ServerHello selecting the same cipher suite. Which of the following is the most significant security concern?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.