← All AAD Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real AAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. Which Android API prevents screenshots and screen recordings of sensitive content within your app?

    Answer: WindowManager.LayoutParams.FLAG_SECURE

    FLAG_SECURE marks a window as containing sensitive content, preventing it from appearing in screenshots or being captured by screen recording tools.

  2. A developer stores an API key directly in the strings.xml resource file. What is the primary risk?

    Answer: The key is extractable via decompiling the APK

    Resource files are bundled into the APK and can be extracted by decompiling the APK with tools like apktool, exposing hardcoded secrets.

  3. What is the recommended mitigation for SQL injection vulnerabilities in Android SQLite databases?

    Answer: Use parameterized queries or prepared statements

    Parameterized queries ensure user input is treated as data rather than executable SQL, preventing injection attacks.

  4. Which mitigation strategy helps detect if an Android app has been tampered with or repackaged by an attacker?

    Answer: Signature verification at runtime

    Checking the app's signing certificate at runtime detects repackaged APKs, since attackers must re-sign the app with a different key.

  5. What risk does an exported Activity with no permission requirement introduce?

    Answer: Any app on the device can launch it, potentially bypassing authentication

    An exported Activity with no android:permission attribute can be started by any app or component on the device, potentially exposing sensitive functionality.

  6. A developer uses MD5 to hash passwords before storing them. Why is this a security risk?

    Answer: MD5 is cryptographically broken and vulnerable to collision and preimage attacks

    MD5 is considered cryptographically broken; attackers use rainbow tables and collision attacks to reverse MD5 hashes quickly.

  7. Which Android security feature isolates each app's data so other apps cannot directly access it without explicit sharing?

    Answer: Android sandbox and app-specific storage

    Android's sandbox model assigns each app a unique user ID and restricts file access to app-specific directories, preventing cross-app data leakage.