An executive returning from an international business trip reports that corporate mobile applications on an enterprise-managed tablet are failing to connect to internal company servers. A security log review reveals that an untrusted third-party root CA certificate was installed on the device while connected to a public hotel network, causing the Mobile Device Management (MDM) client to mark the device as non-compliant and revoke enterprise network access profiles. Which of the following is the FIRST action an administrator should take to resolve the connectivity issue securely?
- Remove the untrusted root certificate, verify MDM policy compliance, and re-issue the enterprise security configuration profile.Answer
- BContact the mobile service carrier to initiate a remote network reset for international roaming data towers.
- CReconfigure the enterprise Wi-Fi access point to use WPA2-Personal with a pre-shared key to bypass compliance validation.
- DEnable side-loading developer permissions on the device to force the corporate applications to trust the newly added root CA.
Answer
Remove the untrusted root certificate, verify MDM policy compliance, and re-issue the enterprise security configuration profile.
The correct response addresses the actual security violation by removing the untrusted root CA certificate that caused the MDM non-compliance state. Once the unauthorized certificate is removed, forcing an MDM compliance check allows the system to re-issue the necessary enterprise connectivity profiles safely.
Step-by-Step Solution
Key Concept
MDM Certificate Compliance and Mobile Security Remediation