
GIAC Mobile Device Security Analyst
Domain 2Objective 3
Reverse Engineering Mobile Applications GMOB Practice Questions (Page 3)
Part of the Mobile Application Analysis and Assessment domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
8concepts
Questions 11–15
- 11
During dynamic analysis of an Android app, an analyst discovers that the app stores sensitive data in a SQLite database that is encrypted with a key derived from a hardcoded string in the app's code. The analyst needs to extract the data for the report. Which approach is most efficient?
Select an answer first - 12
An analyst is reviewing an Android APK that has been obfuscated with ProGuard. The analyst needs to understand the app's logic but the class and method names are meaningless. Which approach is most effective for static analysis?
Select an answer first - 13
An analyst is reverse engineering a heavily obfuscated Android app that uses native code for its core logic. The analyst has identified that the app uses anti-debugging and anti-emulator techniques. The analyst needs to understand the native code's functionality and bypass the protections. Which combination of tools and techniques is most effective?
Select an answer first - 14
An analyst is performing dynamic analysis of an iOS app that uses certificate pinning and also detects if the device is jailbroken. The analyst has a jailbroken device and wants to intercept HTTPS traffic. Which combination of tools is most effective?
Select an answer first - 15
An analyst is analyzing an Android app that uses native code for critical functions. The analyst has already used jadx to decompile the Java code and found that the app loads a native library called 'libcore.so'. The analyst now needs to inspect the native library's functions and look for potential buffer overflows. Which tool is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.