CompTIA
MB0-001 · Question #125
Ann, an attacker, has spoofed a mobile device serial number so she can connect to the MDM environment. Which of the following would an administrator check to uncover this attack?
The correct answer is D. Review recent connection locations, looking for an abnormal location. See the full explanation below for the reasoning.
Question
Ann, an attacker, has spoofed a mobile device serial number so she can connect to the MDM environment. Which of the following would an administrator check to uncover this attack?
Options
- AReview the SIEM logs on a corporate network to determine authentication issues
- BReview certificate revocations by the MDM
- CReview connection attempts to the network from that phone's serial number
- DReview recent connection locations, looking for an abnormal location
How the community answered
(38 responses)- A5% (2)
- B13% (5)
- C3% (1)
- D79% (30)
Community Discussion
No community discussion yet for this question.