Soru

Zorluk: OrtaTroubleshooting Mobile OS Security and Connectivity Issues

A remote employee using a corporate-managed smartphone reports receiving persistent untrusted certificate warnings while attempting to access company resources. An investigation reveals that an unapproved provisioning profile and a untrusted third-party root CA certificate were installed on the device, causing corporate traffic to be intercepted over an unencrypted channel. Which TWO of the following initial remediation steps should the technician perform to secure the device and restore proper connectivity? (Select TWO.)

  1. Remove the unapproved configuration profile and untrusted root certificate from the device settings.Cevap
  2. Revoke device administrator privileges for unverified applications and remove unapproved sideloaded apps.Cevap
  3. C
    Contact the cellular service provider to issue a SIM swap and reset cell tower data routing.
  4. D
    Reconfigure corporate RADIUS servers to bypass client-side CA certificate validation.
  5. E
    Enable OS developer mode and adjust local TCP IP stack socket parameters.

Cevap

The technician should remove the unapproved configuration profile and untrusted root certificate from the device settings, and revoke device administrator privileges for unverified applications.
Removing the rogue configuration profile and untrusted root CA certificate directly removes the mechanism conducting traffic interception. Concurrently, revoking device administrative privileges from unverified applications removes persistent access rights that allowed the unauthorized changes to occur.

Adım Adım Çözüm

1
Inspect installed management management profiles and trusted credential stores on the mobile device.
Identified the unapproved configuration profile causing traffic redirection and the untrusted root CA certificate.
Rogue profiles and certificates allow malicious actors to perform man-in-the-middle (MitM) attacks on secure sessions.
2
Remove the rogue profile and root CA certificate.
Traffic redirection is terminated and default trust stores are restored.
Eliminating the malicious root certificate restores legitimate certificate chain validation.
3
Inspect Device Administrator/Special App Access permissions and uninstall unauthorized applications.
Unapproved applications lose administrative rights to enforce system policies.
Preventing malicious applications from retaining persistent administrative privileges ensures long-term system stability.

Anahtar Kavram

Mobile Profile and Certificate Remediation
Bu soruyu puanla