
GIAC Mobile Device Security Analyst
Domain 2Objective 2
Mobile Application Security Assessments GMOB Practice Questions (Page 5)
Part of the Mobile Application Analysis and Assessment domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
12concepts
Questions 21–25
- 21
Which technique is used to detect tampering with a mobile app?
Select an answer first - 22
An Android app requests the READ_SMS permission at runtime. During your assessment, you find that the app only uses SMS for one-time password (OTP) verification. Which of the following is the most appropriate recommendation?
Select an answer first - 23
Which of the following is a common static analysis tool for Android apps?
Select an answer first - 24
While analyzing a mobile app's architecture, you discover that the app communicates with multiple backend endpoints, including one that uses HTTP (not HTTPS) for a 'non-sensitive' feature. The app also embeds an API key for a third-party analytics service. Which of the following is the most appropriate finding to include in the assessment report?
Select an answer first - 25
A mobile app stores user data in a local database. On Android, the database is stored in the app's private directory and is not encrypted. On iOS, the database is stored in the app's sandbox and is protected by NSFileProtectionComplete. Which platform has a higher risk of data exposure if the device is lost?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.