A mobile technician is responding to an alert indicating that a corporate smartphone has been compromised via an unapproved mobile configuration profile, causing unauthorized background data exfiltration. Place the standard incident response and remediation steps in the correct chronological order from first action to final resolution.
- 1Enable airplane mode on the smartphone to immediately isolate the compromised device from Wi-Fi and cellular networks.
- 2Inspect the device management settings to identify and remove the untrusted configuration profile and associated unauthorized root certificates.
- 3Run an enterprise mobile antimalware scan and verify that the operating system has not been rooted or jailbroken.
- 4Re-enroll the smartphone into the corporate Mobile Device Management (MDM) system to push baseline security policy updates.
Cevap
The correct order of steps for remediating the unauthorized mobile configuration profile is: 1) Enable airplane mode to isolate the device, 2) Remove the unapproved configuration profile and untrusted root certificates, 3) Perform an antimalware scan and check for OS compromises, and 4) Re-enroll the device into the corporate MDM system.
In standardized mobile incident response, containment (isolating the device via airplane mode or disabling interfaces) must always happen first to halt exfiltration. Once contained, the administrator removes the rogue profile and root certificates, scans the OS environment for persistent threats, and finally re-enrolls the clean device into corporate MDM to re-establish secure management.
Adım Adım Çözüm
Anahtar Kavram
Mobile Incident Containment and Profile Remediation Workflows