A systems administrator is responding to a security alert involving several enterprise mobile devices. An audit reveals that users installed an unverified optimization tool from an external website, which prompted the installation of a custom root certificate authority (CA) profile and granted the app elevated system permissions. Consequently, the devices lost access to the corporate 802.1X/WPA3-Enterprise wireless network and triggered unauthorized data access alerts. Which TWO of the following initial remediation steps should the administrator take to resolve the security breach and restore connectivity?
- Remove the untrusted root CA certificate profile from the trusted credential store on each affected device.Cevap
- BContact the cellular service provider to issue replacement SIM cards and reset access point name (APN) settings.
- Revoke the sideloaded application's administrative permissions and uninstall the app from the devices.Cevap
- DReconfigure the corporate wireless access points to use WPA2-Personal pre-shared key (PSK) authentication.
- EFactory reset the corporate wireless access points to clear cached client authentication tokens.
Cevap
The administrator should remove the untrusted root CA certificate profile from the trusted credential store and revoke the sideloaded application's administrative permissions before uninstalling the app.
Remediating unauthorized mobile access caused by sideloaded malicious software requires eliminating both the application itself and any persistence mechanisms it created. Removing the untrusted root CA certificate profile restores proper trust validation for enterprise network authentication (802.1X/WPA3-Enterprise), while revoking permissions and uninstalling the sideloaded application removes the unauthorized access threat vector.
Adım Adım Çözüm
Anahtar Kavram
Remediating Mobile OS Security Compromises and Unauthorized Certificate Profiles