Wireless & Mobile Security Flashcards
7 cards from real ALISON practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Wireless & Mobile Security flashcards as text
What does MDM stand for in the context of enterprise mobile security?
Answer: Mobile Device Management
MDM (Mobile Device Management) is a solution that allows organizations to remotely manage, monitor, and enforce security policies on employee mobile devices.
What is 'jailbreaking' a mobile device?
Answer: Exploiting OS vulnerabilities to remove manufacturer/carrier restrictions and gain root access
Jailbreaking (iOS) or rooting (Android) involves exploiting OS vulnerabilities to gain privileged root access, bypassing built-in security controls and vetting mechanisms.
What is a SIM swapping attack?
Answer: Socially engineering a carrier into transferring a victim's phone number to an attacker-controlled SIM
SIM swapping involves deceiving a mobile carrier's support staff into reassigning a victim's phone number to the attacker's SIM, enabling bypass of SMS-based MFA.
What is the security purpose of certificate pinning in mobile applications?
Answer: To ensure the app only trusts specific certificates, preventing MITM attacks via rogue CAs
Certificate pinning embeds expected certificate fingerprints in the app so it rejects connections that present different certificates, even if signed by a trusted CA, thwarting MITM interception.
What is 'smishing' in mobile security?
Answer: Phishing attacks delivered via SMS text messages
Smishing (SMS phishing) involves sending deceptive text messages that trick recipients into clicking malicious links or providing sensitive information.
Starting with Android 6.0 (Marshmallow), how were app permissions changed to improve security?
Answer: Dangerous permissions must be requested and granted individually at runtime
Android 6.0 introduced runtime permissions, requiring apps to request dangerous permissions (camera, contacts, location) individually when the feature is used, giving users granular control.
What primary security risk does a BYOD (Bring Your Own Device) policy introduce in an enterprise environment?
Answer: Loss of organizational control over device security posture and data handling
BYOD reduces IT control over patching, encryption, and app installation on personal devices, creating risk that corporate data may be stored or transmitted insecurely.