Android Security Flashcards
6 cards from real Android Development practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Android Security flashcards as text
What is SQL injection and how does Room protect against it?
Answer: Room uses parameterized queries with placeholders that prevent user input from being interpreted as SQL
Room's @Query annotation uses parameterized queries where user input is bound as data, not parsed as SQL, preventing injection attacks.
What is the purpose of the android:exported attribute in AndroidManifest.xml?
Answer: To control whether other apps can access the component
android:exported=false prevents other apps from starting or interacting with your Activity, Service, or BroadcastReceiver.
Which HTTPS security feature verifies the server's identity using a predefined certificate fingerprint?
Answer: Certificate Pinning
Certificate pinning embeds the expected server certificate or public key hash in the app, rejecting connections with certificates that don't match.
What does the FLAG_SECURE window flag do in Android?
Answer: Prevents the screen content from appearing in screenshots and screen recordings
FLAG_SECURE marks an Activity's window as secure, preventing its content from appearing in screenshots, recent apps thumbnails, and screen recordings.
Which Android feature prevents apps from running unsigned or tampered code?
Answer: APK Signature Verification
APK Signature Verification ensures that apps are signed with a trusted key and have not been tampered with since signing.
What is the purpose of the EncryptedSharedPreferences in Android?
Answer: To encrypt both keys and values stored in SharedPreferences
EncryptedSharedPreferences from Jetpack Security encrypts both the keys and values using AES-256, protecting sensitive preference data at rest.