A user reports that a corporate-issued smartphone recently began displaying intrusive pop-up advertisements on the home screen. Additionally, the device occasionally drops its Wi-Fi connection and redirects web traffic to unknown external IP addresses. A technician inspects the device and finds that a system optimization utility was manually installed via an untrusted APK file. Which of the following actions should the technician take FIRST?
- Disconnect the device from all networks, then uninstall the sideloaded application and its associated profile.Cevap
- BContact the cellular service provider to issue a SIM card profile update and reset cellular tower credentials.
- CPerform an immediate factory reset of the smartphone without inspecting installed application permissions.
- DReconfigure the corporate wireless access points to switch from WPA3-Enterprise authentication to WPA2-Personal.
Cevap
Disconnect the device from all networks, then uninstall the sideloaded application and its associated profile.
Isolating the device from wireless and cellular networks immediately stops active background traffic and redirection attempts. Removing the manually installed sideloaded application and any rogue configuration profiles removes the source of unauthorized behavior without resorting to unnecessary full system resets.
Adım Adım Çözüm
Anahtar Kavram
Incident Isolation and Remediation of Sideloaded Mobile Malware