A desktop technician is responding to a security incident involving a corporate-managed mobile device that automatically connected to a rogue wireless access point and began exhibiting signs of unauthorized data access. In what order should the technician execute the following remediation steps?
- 1Enable Airplane Mode on the mobile device to disable all wireless radios.
- 2Remove untrusted Wi-Fi network profiles and rogue digital certificates from the OS settings.
- 3Perform a complete mobile malware scan and audit application permission grants.
- 4Reconnect to the secure network and synchronize with the Mobile Device Management (MDM) server.
Cevap
The proper remediation sequence begins with enabling Airplane Mode to isolate the device, followed by deleting untrusted Wi-Fi profiles and certificates, running a full malware scan and permission audit, and concluding with MDM resynchronization.
The standard incident response sequence requires immediate containment first (disabling radios via Airplane Mode), followed by clearing the unauthorized persistence settings (profiles/certificates), checking local software integrity (malware scan/permission audit), and finally reconnecting to management infrastructure (MDM sync).
Adım Adım Çözüm
Anahtar Kavram
Mobile Device Security Remediation and Incident Response Workflow
Tahmini Süre:1m 30s