Android Security Flashcards
6 cards from real Android Development practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Android Security flashcards as text
What is the purpose of BiometricPrompt in Android?
Answer: To authenticate users using fingerprint, face, or device credentials
BiometricPrompt provides a standardized API for authenticating users with biometrics or device credentials like PIN/password.
Which Android API is used to detect if the device is rooted or compromised?
Answer: Both A and B
Both the Play Integrity API (current) and the deprecated SafetyNet Attestation API assess device integrity and detect rooting or tampering.
What is the principle of least privilege in Android development?
Answer: Requesting only the permissions absolutely necessary for the app to function
The principle of least privilege means declaring only the minimum required permissions to reduce the attack surface and potential harm if the app is compromised.
Which method should you override to handle the result of a runtime permission request?
Answer: onRequestPermissionsResult
onRequestPermissionsResult is called after the user responds to a permission request dialog, providing the granted or denied results.
What does deep link validation involve in Android security?
Answer: Verifying that incoming deep link data is sanitized before use to prevent injection attacks
Deep link validation requires sanitizing and validating all parameters from incoming URIs to prevent injection and unintended navigation.
Which type of Android storage is isolated per app and not accessible to other apps without permission?
Answer: Internal storage (app-private)
Internal storage is app-private by default — files stored there are inaccessible to other apps and are deleted when the app is uninstalled.