
GIAC Mobile Device Security Analyst
Domain 2Objective 2
Mobile Application Security Assessments GMOB Practice Questions (Page 12)
Part of the Mobile Application Analysis and Assessment domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 56–58
- 56
You are threat modeling a mobile payment app. The app allows users to send money to other users via a backend API. Which of the following is the most critical asset to protect in your threat model?
Select an answer first - 57
During static analysis of a mobile app, you find that it uses AES in ECB mode to encrypt a user's personal identification number (PIN) before storing it locally. What is the most significant issue with this implementation?
Select an answer first - 58
Which of the following is a common cryptographic implementation flaw in mobile apps?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GMOB
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.