A technician is responding to a security incident where a corporate smartphone automatically connected to an unencrypted rogue Wi-Fi access point, exposing active enterprise user tokens. In what order should the technician perform the following steps to properly isolate, remediate, and restore the mobile device?
- 1Isolate the mobile device from all wireless networks by placing it into Airplane Mode.
- 2Revoke active enterprise authentication tokens and reset the user's corporate password.
- 3Inspect the device network configuration and saved Wi-Fi profiles to identify the cause of the connection.
- 4Remove untrusted Wi-Fi profiles and disable the option to automatically connect to open networks.
- 5Perform a Mobile Device Management (MDM) compliance check before re-enabling enterprise network access.
Answer
The technician should first isolate the device by enabling Airplane Mode, revoke corporate credentials and tokens next, inspect saved network settings to find the vulnerability vector, delete untrusted profiles while disabling auto-connect, and finally verify MDM compliance before restoring network access.
In mobile security incident management, immediate isolation (enabling Airplane Mode) must happen first to stop data leakage. Next, identity containment occurs by revoking compromised tokens and passwords. Then, the technician investigates the device configuration to identify saved profiles or auto-connect behaviors. Remediation follows by deleting untrusted profiles and turning off auto-connect to open networks. Finally, device posture is verified through MDM compliance checks before returning the device to standard operations.
Step-by-Step Solution
Key Concept
Mobile Incident Response Workflow: Containment, Credential Protection, Root Cause Analysis, Remediation, and Re-enrollment Verification