Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Mobile Device Security Analyst

Domain 2Objective 3

Reverse Engineering Mobile Applications GMOB Practice Questions (Page 5)

Part of the Mobile Application Analysis and Assessment domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts

Questions 21–25

  1. 21application · medium

    An analyst is performing dynamic analysis of an Android app that detects whether it is running on an emulator. The app refuses to launch under the standard Android Emulator. The analyst needs to continue testing without modifying the app's code. Which approach is most effective?

    Select an answer first
  2. 22expert · hard

    An analyst is reverse engineering an iOS app that uses a native library for cryptographic operations. The analyst has identified that the library is statically linked and contains symbols. The analyst needs to determine whether the library uses a known vulnerable version of a cryptographic library. Which approach is most efficient?

    Select an answer first
  3. 23foundation · easy

    Which technique involves running a mobile app in a controlled environment to observe its runtime behavior, such as network calls and file system changes?

    Select an answer first
  4. 24expert · hard

    A security team has completed a reverse engineering assessment of a mobile app and found several vulnerabilities, including hardcoded API keys, insecure data storage, and a lack of certificate pinning. The team must present the findings to the development team and management. The management wants to know the business impact, while the developers need to know how to fix the issues. What is the best way to structure the report?

    Select an answer first
  5. 25application · medium

    After completing a reverse engineering assessment of a mobile banking app, an analyst must present the findings to a mixed audience of developers, security managers, and executives. The report should highlight the most critical security risks and provide actionable recommendations. What is the most effective way to structure the report?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GMOB” is a trademark of its owner, used for identification only.