During a security audit at a branch office, an IT administrator observes that several corporate smartphones are exhibiting abnormal routing behavior, where internal web applications display security certificate warnings. Further investigation reveals that a malicious utility sideloaded by users created an unauthorized local VPN profile and added an untrusted Root CA certificate to the system trust store, causing the Mobile Device Management (MDM) system to mark the devices as non-compliant and quarantine them. Which of the following actions should the technician perform FIRST to remediate the security compromise on these devices?
- Remove the unauthorized local VPN configuration, delete the untrusted Root CA certificate, and uninstall the sideloaded application.Cevap
- BContact the mobile service provider to report a cell site outage and request fresh SIM card provisioning.
- CReconfigure the network access points to switch from WPA3-Enterprise to WPA2-Personal authentication.
- DIssue an immediate carrier-level full device wipe through the cellular service portal.
Cevap
Remove the unauthorized local VPN configuration, delete the untrusted Root CA certificate, and uninstall the sideloaded application.
Removing the untrusted local VPN profile, purging the malicious Root CA certificate from the mobile OS trust store, and uninstalling the sideloaded application directly eliminates the unauthorized access vector. Once these items are removed, the device complies with corporate security policies, allowing the MDM server to lift the quarantine.
Adım Adım Çözüm
Anahtar Kavram
Remediating Mobile Device Security Profile and Certificate Interception