A corporate mobile user reports receiving frequent untrusted root certificate warnings while connected to external networks. Shortly after, security alerts indicate unauthorized login attempts on the user's corporate Single Sign-On (SSO) account. A technician inspects the mobile device and discovers an unapproved custom VPN configuration profile routing all encrypted traffic through a rogue proxy server. Which of the following is the BEST sequence of actions to resolve the security compromise and protect corporate data?
- Remove the untrusted VPN profile, reset the user's SSO credentials, and re-enroll the device in the Mobile Device Management (MDM) portal.Answer
- BUpdate the cellular Access Point Name (APN) settings on the device to switch network routing away from the carrier.
- CReconfigure the public wireless network router to force WPA3-Enterprise authentication for all connected clients.
- DPerform a soft reset on the mobile phone and clear the cached history of the native web browser.
Answer
Remove the untrusted VPN profile, reset the user's SSO credentials, and re-enroll the device in the Mobile Device Management (MDM) portal.
The correct response addresses both the root cause on the device (the malicious VPN profile intercepting traffic) and the secondary impact (compromised corporate account credentials). Removing the profile halts unauthorized traffic redirection, resetting credentials revokes compromised access, and MDM re-enrollment restores enforced security baselines.
Step-by-Step Solution
Key Concept
Mobile OS Security and Malicious Profile Remediation
Estimated Time:1m 30s