220-1102 · Question #1
A user's mobile phone has become sluggish. A systems administrator discovered several malicious applications on the device and reset the phone. The administrator installed MDM software. Which of the f
The correct answer is A. Prevent a device root E. Block a third-party application installation. After a mobile phone reset and MDM installation, an administrator should prevent device rooting and block third-party app installations to enhance security against future malware threats. These measures limit unauthorized system access and control app sources, respectively.
Question
A user's mobile phone has become sluggish. A systems administrator discovered several malicious applications on the device and reset the phone. The administrator installed MDM software. Which of the following should the administrator do to help secure the device against this threat in the future? (Choose two.)
Options
- APrevent a device root
- BDisable biometric authentication
- CRequire a PIN on the unlock screen
- DEnable developer mode
- EBlock a third-party application installation
- FPrevent GPS spoofing
How the community answered
(28 responses)- A75% (21)
- B7% (2)
- C4% (1)
- D4% (1)
- F11% (3)
Why each option
After a mobile phone reset and MDM installation, an administrator should prevent device rooting and block third-party app installations to enhance security against future malware threats. These measures limit unauthorized system access and control app sources, respectively.
Preventing a device root, or jailbreaking, stops users from gaining privileged control over the operating system, which is a common prerequisite for malicious apps to deeply compromise the device and bypass security controls. MDM software often includes features to detect and prevent rooted devices from accessing corporate resources or to wipe them if rooted.
Disabling biometric authentication would reduce convenience without directly preventing malicious application installation; in fact, it might decrease overall device security by making it easier for an unauthorized person to access a lost or stolen device if a weaker authentication method is used.
While requiring a PIN on the unlock screen is a good security practice, it primarily protects against unauthorized physical access to the device and does not directly prevent the installation or execution of malicious applications.
Enabling developer mode often relaxes security settings and allows for advanced debugging and sideloading, which would increase the device's vulnerability to malicious applications, directly opposing the goal of securing the device.
Blocking third-party application installations means restricting app sources to official app stores (like Google Play Store or Apple App Store), significantly reducing the risk of installing malicious software from untrusted sources. MDM solutions allow administrators to enforce this policy, preventing users from sideloading potentially harmful applications.
Preventing GPS spoofing addresses location-based attacks but does not directly prevent the installation of malicious applications that caused the initial sluggishness.
Concept tested: Mobile device security policies via MDM
Source: support.apple.com/guide/deployment/ios-ipados-security-overview-dep96d747065/web
Topics
Community Discussion
No community discussion yet for this question.