Soru

Zorluk: OrtaTroubleshooting Mobile OS Security and Connectivity Issues

A logistics coordinator reports that after downloading a third-party navigation utility onto a company smartphone from an untrusted web repository, the device began displaying persistent requests for elevated system rights and generating unauthorized background network activity. Which of the following actions should an IT technician take FIRST to remediate this security risk?

  1. Disconnect the smartphone from all Wi-Fi and cellular networks to isolate the device.Cevap
  2. B
    Contact the cellular service provider to report a localized network outage and request a SIM swap.
  3. C
    Reconfigure the device network settings to default to WPA2-Personal authentication.
  4. D
    Grant the application device administrator privileges to clear the system prompts.

Cevap

Disconnect the smartphone from all Wi-Fi and cellular networks to isolate the device.
The immediate first step in responding to a suspected mobile security compromise is isolation. Placing the device in Airplane mode or disabling all network adapters (cellular and Wi-Fi) stops unauthorized background communication and prevents data exfiltration.

Adım Adım Çözüm

1
Identify the symptoms of a mobile security compromise.
Recognized that the unauthorized third-party application is requesting administrative rights and transmitting unauthorized background data.
Sideloaded apps from untrusted sources frequently bundle malicious code capable of data exfiltration.
2
Execute initial containment procedures.
Place the device into Airplane mode or turn off all Wi-Fi and cellular connections.
Isolation stops external data leakage and prevents command-and-control communications before proceeding with malware removal.
3
Proceed with remediation and app removal.
Revoke permissions, uninstall the malicious utility, and inspect MDM compliance.
Ensures the device is clean before reconnecting to the network.

Anahtar Kavram

Mobile Device Security Incident Containment
Bu soruyu puanla