โ† All AAD Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real AAD practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. What is the recommended way to store OAuth tokens securely on Android?

    Answer: In the Android Keystore System or EncryptedSharedPreferences

    The Android Keystore System stores cryptographic keys in hardware-backed secure storage, and EncryptedSharedPreferences encrypts data at rest.

  2. Which risk is mitigated by setting android:allowBackup="false" in the AndroidManifest.xml?

    Answer: Blocking ADB backup extraction of the app's private data

    With allowBackup=true (the default), ADB backup can extract app data without root access; setting it to false blocks this extraction path.

  3. A third-party SDK included in an Android app requests the CONTACTS permission. What risk management practice should be applied?

    Answer: Audit SDK permissions and use Permission Reviewer or a dependency scanner to assess necessity

    Third-party SDKs can merge permissions into the final manifest; auditing SDK requirements ensures no unnecessary or risky permissions are granted.

  4. What is a primary risk of using Android's WebView to load untrusted external URLs without disabling JavaScript?

    Answer: Cross-site scripting (XSS) attacks can execute arbitrary JavaScript in the app's context

    JavaScript enabled in a WebView loading untrusted content can execute scripts that access native Android bridges or steal app data via XSS.

  5. What does enabling StrictMode in Android development help identify?

    Answer: Policy violations like disk I/O or network calls on the main thread, which can cause ANR risks

    StrictMode detects inadvertent disk or network access on the main thread that could lead to Application Not Responding (ANR) errors in production.

  6. Which practice reduces the risk of memory leaks caused by non-static inner classes in Android?

    Answer: Using static inner classes with WeakReferences to the outer context

    Static inner classes don't hold an implicit reference to the outer Activity, and WeakReferences allow the GC to collect the Activity when no longer needed.

  7. A release build APK is published without running ProGuard/R8 obfuscation. What specific risk increases?

    Answer: Reverse engineers can more easily read class names and business logic by decompiling the APK

    Without obfuscation, decompiled code retains meaningful class and method names, making it easier for attackers to understand and exploit app logic.