
GIAC Mobile Device Security Analyst
Domain 4Objective 2
Mitigating Against Mobile Malware GMOB Practice Questions (Page 8)
Part of the Mobile Malware and Application Behavior domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 36–40
- 36
A company wants to implement a layered defense against mobile malware. Which set of measures represents a defense-in-depth approach?
Select an answer first - 37
A company's mobile devices are infected with malware that uses a legitimate cloud service for C2. The security team has identified the malware and wants to disrupt the C2 channel. The malware uses HTTPS to communicate with the cloud service, and the company has a next-generation firewall (NGFW) that can decrypt HTTPS. Which action is most effective?
Select an answer first - 38
A company's employees frequently travel and use public Wi-Fi in airports and hotels. The security team wants to reduce the risk of malware communicating with C2 servers. Which network security measure is most effective?
Select an answer first - 39
A security analyst is reviewing an Android app that was approved by the Google Play Store. The app requests permissions to access the camera, microphone, and location. The app's functionality does not appear to require these permissions. What should the analyst conclude?
Select an answer first - 40
What is the primary purpose of the permission model on mobile operating systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.