A remote employee reports that while working in a public venue, their corporate-managed smartphone automatically connected to an open Wi-Fi hotspot broadcasting a SSID identical to their office network. Shortly after, corporate email syncing failed, and the device displayed continuous background location tracking activity. Upon inspection, an IT technician suspects a rogue access point attack compromised the device by installing a malicious management payload. Which TWO of the following actions should the technician perform immediately to remediate the security breach and restore secure operation?
- Remove the malicious configuration profile from the mobile operating system security settings.Cevap
- BPerform a complete remote wipe of the device's internal storage before initiating re-enrollment.
- Revoke and reset the user's corporate account credentials and authentication tokens.Cevap
- DChange the corporate wireless network profile authentication standard from WPA3-Enterprise to TKIP.
- ESubmit an urgent service ticket to the cellular service provider to report local tower outages.
Cevap
The technician should remove the malicious configuration profile from the security settings and revoke/reset the user's corporate credentials.
When a mobile device connects to a rogue access point, attackers often push untrusted configuration profiles containing rogue certificates or malicious settings. Removing the bad configuration profile cleans the device's certificate store, while resetting corporate user credentials prevents account takeover using credentials captured during the man-in-the-middle interception.
Adım Adım Çözüm
Anahtar Kavram
Mobile security profile remediation and rogue access point incident response