Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Mobile Device Security Analyst

Domain 4Objective 1

Manipulating Mobile Application Behavior GMOB Practice Questions (Page 2)

Part of the Mobile Malware and Application Behavior domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 6–10

  1. 6application · medium

    A security analyst is investigating a malicious app that was distributed via a third-party app store. The app appears to be a legitimate game, but it also sends the user's contacts to a remote server. Which attack vector is most likely?

    Select an answer first
  2. 7application · medium

    A security analyst is investigating a mobile app that has been reported to behave differently on rooted devices. On a rooted device, the app displays an error message and exits, but on a non-rooted device it functions normally. The analyst suspects the app is using root detection. Which manipulation technique could an attacker use to bypass this root detection?

    Select an answer first
  3. 8application · medium

    A security analyst discovers that a popular app has been repackaged and distributed on third-party app stores. The repackaged version contains a malicious library that steals credentials. Which indicator would most reliably identify the repackaged version?

    Select an answer first
  4. 9expert · hard

    A mobile app team is deciding between two anti-tampering strategies: (1) implementing runtime integrity checks that detect hooking frameworks, or (2) using code obfuscation to make reverse engineering harder. The team has limited development resources and wants to maximize protection against both runtime manipulation and static repackaging. Which strategy should they choose?

    Select an answer first
  5. 10application · medium

    A mobile app development team wants to detect if their Android app has been repackaged and distributed outside the official store. They plan to implement a runtime integrity check. Which approach would be most effective at detecting repackaging?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.