Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Mobile Device Security Analyst

Domain 3Objective 1

Attacking Encrypted Traffic GMOB Practice Questions (Page 3)

Part of the Network Traffic Manipulation and Security domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)

50questions here
10free pages
9concepts

Questions 11–15

  1. 11foundation · easy

    A mobile app is vulnerable to man-in-the-middle attacks because it does not properly validate server certificates. Which of the following is the most effective mitigation?

    Select an answer first
  2. 12application · medium

    A penetration tester is assessing a mobile app that uses TLS 1.2. The tester wants to test if the server can be forced to use a weaker cipher suite. Which tool or technique would be most appropriate?

    Select an answer first
  3. 13application · medium

    A security analyst is testing the organization's mobile device management (MDM) solution. The analyst wants to verify that the MDM agent properly validates the server certificate when communicating with the MDM server. The analyst sets up a rogue access point and uses a proxy to intercept the agent's traffic. The agent connects successfully, but the analyst cannot see the plaintext traffic. Which action would most likely allow the analyst to view the plaintext traffic?

    Select an answer first
  4. 14foundation · easy

    During a network capture, an analyst sees a large volume of TLS-encrypted traffic. Which of the following is the most reliable way to determine the application-layer protocol (e.g., HTTP, SMTP) being used inside the TLS tunnel?

    Select an answer first
  5. 15foundation · easy

    An attacker forces a client and server to negotiate a weaker encryption protocol, such as SSL 3.0 instead of TLS 1.2, to exploit known vulnerabilities. What is this attack technique called?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.