A security administrator discovers that a corporate mobile device was connected to an unauthorized rogue Wi-Fi access point and subsequently installed a malicious configuration profile. Place the following remediation steps in the correct chronological order to contain the incident and restore the device to a secure state.
- 1Disconnect and isolate the mobile device from all cellular and enterprise wireless networks.
- 2Remove the unauthorized configuration profile and untrusted root certificates from the device settings.
- 3Reset compromised user credentials and run a full security scan to verify OS integrity.
- 4Re-enroll the mobile device into the enterprise Mobile Device Management (MDM) portal to enforce compliant security policies.
Cevap
The correct sequence begins with network isolation of the compromised mobile device, followed by removing the malicious configuration profile and root certificates, revoking and updating compromised account credentials while scanning for malware, and finally re-enrolling the device into enterprise Mobile Device Management (MDM).
In CompTIA security troubleshooting procedures, containment (disconnecting network interfaces) must take place before remediation (deleting rogue profiles/certificates and resetting passwords). Once the device is remediated and verified clean, recovery (MDM re-enrollment and policy deployment) restores secure operational status.
Adım Adım Çözüm
Anahtar Kavram
Mobile Device Incident Response and Security Remediation Workflow