
GIAC Mobile Device Security Analyst
Domain 2Objective 3
Reverse Engineering Mobile Applications GMOB Practice Questions (Page 1)
Part of the Mobile Application Analysis and Assessment domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 1–5
- 1
An analyst is performing dynamic analysis on an Android app and wants to capture the network traffic between the app and its backend server. The app uses HTTPS, and the analyst has installed a custom CA certificate on the emulator. However, the app is using certificate pinning and rejects the custom CA. Which technique should the analyst use to bypass certificate pinning?
Select an answer first - 2
An analyst is comparing two versions of an Android app to identify changes in the native code. The analyst has the APK files for both versions. Which approach is most efficient for identifying changes in the native libraries?
Select an answer first - 3
Which tool is specifically designed to decompile Android APK files into readable Java source code?
Select an answer first - 4
An analyst needs to decode an Android app's resources and view its smali code. Which tool is best suited for this task?
Select an answer first - 5
During dynamic analysis of an Android app, an analyst wants to capture the network traffic to see if the app sends sensitive data in cleartext. The app does not use certificate pinning. Which setup is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.