
GIAC Mobile Device Security Analyst
Domain 4Objective 2
Mitigating Against Mobile Malware GMOB Practice Questions (Page 9)
Part of the Mobile Malware and Application Behavior domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 41–45
- 41
A company's mobile devices are configured to use a VPN for all traffic. However, some users report that certain apps do not work when the VPN is enabled. The security team suspects that the VPN is blocking traffic to legitimate services. What is the best approach to maintain security while resolving the issue?
Select an answer first - 42
An organization is considering allowing employees to use a third-party app store to access a niche productivity tool not available in the official store. The security team is asked to evaluate the risk. What is the primary security concern with this approach?
Select an answer first - 43
What is the primary purpose of app vetting as a mobile malware mitigation strategy?
Select an answer first - 44
An organization is deploying Android devices with a custom enterprise app. They want to limit the app's access to sensitive data if the device is compromised. Which configuration best leverages Android's permission model?
Select an answer first - 45
An employee wants to install an app that is not available in the official app store but is popular on a third-party website. The app requests access to contacts and SMS. What should the security team advise?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.