
GIAC Mobile Device Security Analyst
Domain 3Objective 1
Attacking Encrypted Traffic GMOB Practice Questions (Page 7)
Part of the Network Traffic Manipulation and Security domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 31–35
- 31
An attacker obtains a valid certificate for a domain they do not own from a compromised or negligent certificate authority. What is this type of attack called?
Select an answer first - 32
A security analyst is testing a mobile web app that uses HSTS. The analyst wants to perform an SSL stripping attack. Which condition would make the attack possible?
Select an answer first - 33
An attacker intercepts a user's request to a website and modifies the URL from 'https://example.com' to 'http://example.com' before forwarding it. What is this attack called?
Select an answer first - 34
A security researcher is analyzing a mobile app that uses TLS to communicate with a backend server. The researcher has obtained the app's binary and wants to extract the TLS session keys from the device to decrypt traffic. Which of the following approaches is most likely to succeed?
Select an answer first - 35
A security team is hardening a mobile app's TLS implementation. The team wants to prevent downgrade attacks and rogue certificate attacks. Which combination of controls would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.