
GIAC Mobile Device Security Analyst
Domain 3Objective 1
Attacking Encrypted Traffic GMOB Practice Questions (Page 4)
Part of the Network Traffic Manipulation and Security domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 16–20
- 16
A security analyst is monitoring a corporate network and notices that a mobile device is sending a large amount of data to a cloud storage service using TLS. The analyst suspects data exfiltration but cannot decrypt the traffic. Which detection technique would be most effective?
Select an answer first - 17
A penetration tester is assessing a mobile banking app. The app uses certificate pinning and only allows HTTPS connections. The tester wants to capture the app's API traffic. Which approach is most likely to succeed?
Select an answer first - 18
A penetration tester is performing a wireless assessment. The tester wants to intercept and decrypt HTTPS traffic from a mobile device on the same Wi-Fi network. The tester has already installed a rogue CA certificate on the device. Which additional step is required to complete the MITM attack?
Select an answer first - 19
A security analyst is testing a mobile app's TLS implementation. The analyst notices that the app accepts any certificate signed by a CA that is in the device's trust store. The analyst wants to test the app's resistance to rogue CA attacks. Which action would be most effective?
Select an answer first - 20
A network security team is trying to detect data exfiltration over encrypted tunnels. They have implemented a solution that inspects TLS handshake metadata and flags connections to known file-sharing services. However, they are seeing many false positives because employees legitimately use these services. Which of the following enhancements would most reduce false positives while still detecting exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.