← All AAD Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real AAD practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. What is the purpose of certificate pinning in Android network security?

    Answer: To prevent man-in-the-middle attacks by validating the server's expected certificate

    Certificate pinning rejects connections to servers presenting unexpected certificates, stopping MITM attacks even from compromised certificate authorities.

  2. Which Gradle configuration option enables R8/ProGuard to reduce attack surface by removing unused code from the release APK?

    Answer: minifyEnabled true

    Setting minifyEnabled true activates R8/ProGuard code shrinking, removing unused classes and methods that could otherwise be exploited.

  3. A user's Android device is stolen while unlocked. What app-level mitigation best protects sensitive data in this scenario?

    Answer: Requiring re-authentication after a short inactivity timeout

    Requiring re-authentication after a timeout ensures that even physical access to an unlocked device does not bypass in-app authentication.

  4. What risk is introduced when an app logs sensitive user data using Log.d() in production builds?

    Answer: Sensitive data can be read from device logs by other apps with READ_LOGS permission or via ADB

    Android logs can be accessed via ADB or by apps with READ_LOGS permission, making production debug logs a data leakage risk.

  5. Which approach mitigates the risk of sensitive data persisting in Android's task switcher (recent apps screen)?

    Answer: Using FLAG_SECURE or excluding the Activity from the Recents screen

    FLAG_SECURE prevents the system from capturing a snapshot of the window for the Recents screen, protecting sensitive content from being visible.

  6. Why should Android apps avoid storing sensitive data in External Storage (e.g., SD card)?

    Answer: Any app with READ_EXTERNAL_STORAGE permission can access files on external storage

    External storage is world-readable to apps holding READ_EXTERNAL_STORAGE permission, making it unsuitable for private or sensitive files.

  7. An Android app accepts deep link URLs without validating the host or path. What attack does this enable?

    Answer: Deep link hijacking or unauthorized access to in-app screens

    Unvalidated deep links allow malicious apps or websites to craft URLs that open protected in-app screens or trigger privileged actions.