220-1002 · Question #89
Ann, a smartphone user receives an in-app notification that her third party note taking app has an update that requires additional permissions. The update requires access to connected storage…
The correct answer is D. Refuse the app update. The IT department should refuse the update. Requesting access to networked storage and the ability to enable or disable airplane mode is far outside the expected functional scope of a note-taking application. These permissions could enable unauthorized data exfiltration via…
Question
Ann, a smartphone user receives an in-app notification that her third party note taking app has an update that requires additional permissions. The update requires access to connected storage, including networked resources, and the ability to enable or disable airplane mode. She has consulted the company's IT department about the situation. Which of the following is the BEST course of action for the IT department to recommend?
Options
- AAccept the app update
- BUninstall the app
- CPostpone the app update
- DRefuse the app update
How the community answered
(67 responses)- A28% (19)
- B6% (4)
- C10% (7)
- D55% (37)
Explanation
The IT department should refuse the update. Requesting access to networked storage and the ability to enable or disable airplane mode is far outside the expected functional scope of a note-taking application. These permissions could enable unauthorized data exfiltration via network shares and allow the app to circumvent network security controls by manipulating connectivity. This permission creep is a clear red flag for malicious or compromised software. Accepting or merely postponing leaves the organization exposed; refusing the update blocks the risk while the app continues to function in its current, presumably safe, state.
Topics
Community Discussion
No community discussion yet for this question.