Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Mobile Device Security Analyst

Domain 3Objective 2

Manipulating Network Traffic GMOB Practice Questions (Page 3)

Part of the Network Traffic Manipulation and Security domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
7concepts

Questions 11–15

  1. 11expert · hard

    An analyst is testing a mobile app that uses TLS with mutual authentication (mTLS). The analyst has intercepted the traffic and wants to decrypt it. The analyst has the app's client certificate and private key. Which additional configuration is required in the proxy to successfully decrypt the traffic?

    Select an answer first
  2. 12application · medium

    While analyzing intercepted traffic from a mobile banking app, a tester notices that the session cookie is not marked with the Secure flag and is sent over HTTP when the app falls back to a non-TLS connection. The tester wants to demonstrate the risk of session hijacking. Which action best proves the vulnerability?

    Select an answer first
  3. 13application · medium

    After intercepting HTTPS traffic from a mobile app, an analyst sees a request to an endpoint that returns a JSON response with a field named 'isAdmin' set to false. The analyst wants to test if the server properly enforces authorization. Which action is most appropriate?

    Select an answer first
  4. 14application · medium

    An analyst is testing a mobile banking app for authorization flaws. The analyst intercepts a request to view account details and notices the request includes a numeric account ID in the URL. The analyst wants to test if the server properly verifies that the authenticated user owns the account. Which action should the analyst take?

    Select an answer first
  5. 15expert · hard

    A tester is fuzzing a mobile app's API and wants to identify input validation vulnerabilities. The tester has captured a valid request and wants to fuzz the 'id' parameter. Which approach is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.