nerdexam
CompTIA

MB0-001 · Question #125

Ann, an attacker, has spoofed a mobile device serial number so she can connect to the MDM environment. Which of the following would an administrator check to uncover this attack?

The correct answer is D. Review recent connection locations, looking for an abnormal location. See the full explanation below for the reasoning.

Question

Ann, an attacker, has spoofed a mobile device serial number so she can connect to the MDM environment. Which of the following would an administrator check to uncover this attack?

Options

  • AReview the SIEM logs on a corporate network to determine authentication issues
  • BReview certificate revocations by the MDM
  • CReview connection attempts to the network from that phone's serial number
  • DReview recent connection locations, looking for an abnormal location

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    13% (5)
  • C
    3% (1)
  • D
    79% (30)

Community Discussion

No community discussion yet for this question.

Full MB0-001 Practice