A mobile user reports that their corporate smartphone is experiencing severe battery drain, sending unauthorized SMS messages, and displaying certificate warning pop-ups. A technician determines that an untrusted configuration profile was installed via a phishing link.
Place the following incident response and remediation steps in the correct chronological order to mitigate the threat and securely restore the device.
- 1Disconnect the device from all cellular and Wi-Fi networks.
- 2Remove the malicious configuration profile and unapproved application from the mobile OS settings.
- 3Perform a complete system antimalware scan and verify operating system integrity.
- 4Re-enroll the smartphone into the Enterprise Mobile Device Management (MDM) platform.
Answer
The proper sequence to remediate the compromised mobile device is: 1) Disconnect the device from all cellular and Wi-Fi networks, 2) Remove the malicious configuration profile and unapproved application from the mobile OS settings, 3) Perform a complete system antimalware scan and verify operating system integrity, and 4) Re-enroll the smartphone into the Enterprise Mobile Device Management (MDM) platform.
When troubleshooting mobile security incidents, containment must occur before remediation. First, isolating the device from Wi-Fi and cellular networks stops remote attack vectors and exfiltration. Next, removing the rogue profile and malicious application clears unauthorized settings and administrative rights. Then, scanning the device verifies eradication of hidden malicious components. Finally, re-enrolling the clean device into the Enterprise MDM reinstates trusted security profiles and access rights.
Step-by-Step Solution
Key Concept
Mobile Device Security Incident Response Workflow