Question

Difficulty: MediumTroubleshooting Mobile OS Security and Connectivity Issues

A sales representative using a corporate-managed Android smartphone reports that after manually installing an APK file from an untrusted website, the phone began displaying frequent pop-up advertisements and requesting elevated Device Administrator permissions. Which of the following actions should the technician take FIRST to contain the potential security incident without destroying device evidence?

  1. Enable Airplane Mode on the device to disconnect it from cellular and wireless networks.Answer
  2. B
    Initiate a full remote wipe of the device through the corporate Mobile Device Management console.
  3. C
    Contact the cellular service provider to report a localized cell tower connectivity outage.
  4. D
    Reconfigure the corporate Wi-Fi profile on the device to use WPA2-Personal security.

Answer

Enable Airplane Mode on the device to disconnect it from cellular and wireless networks.
Enabling Airplane Mode immediately isolates the compromised mobile device from cellular and Wi-Fi networks, preventing unauthorized command-and-control communication or data exfiltration while preserving device memory state for investigation.

Step-by-Step Solution

1
Identify the primary security risk posed by the untrusted sideloaded APK.
Recognize that malicious software may establish active background connections to remote servers or exfiltrate sensitive data.
Sideloaded applications bypass official app store security screening and often request administrative privileges.
2
Select the immediate containment control.
Isolate the device from external communications by toggling Airplane Mode on.
Network isolation prevents data exfiltration and blocks command-and-control communication without destroying system logs.

Key Concept

Mobile Device Security Incident Containment and Isolation
Rate this question