
GIAC Mobile Device Security Analyst
Domain 3Objective 1
Attacking Encrypted Traffic GMOB Practice Questions (Page 8)
Part of the Network Traffic Manipulation and Security domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 36–40
- 36
A security team is testing a mobile app that uses TLS 1.2 with certificate pinning. The team wants to test the app's resistance to downgrade attacks. The app is installed on a test device that is rooted. Which approach would be most effective?
Select an answer first - 37
A network administrator notices a mobile device regularly connecting to a remote server on TCP port 443, but the traffic patterns are unusual: the packets are small, frequent, and occur at regular intervals. The administrator suspects data exfiltration. Which action would be most effective to confirm the suspicion?
Select an answer first - 38
A forensic analyst is examining a mobile device that was used to access a corporate webmail service. The analyst has a full packet capture of the device's network traffic, but the TLS session is encrypted. The analyst also has a memory dump of the device. Which technique would be most effective to decrypt the TLS session?
Select an answer first - 39
A mobile app connects to a server using TLS. The app's certificate validation process checks that the certificate is signed by a trusted root CA and that the certificate has not expired. Which critical validation step is missing from this process?
Select an answer first - 40
Which of the following is a common defense against SSL stripping attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.