Skip to content
ScopefileGet the app

Module 17Domain 7 of 9Mobile Platform, IoT, and OT Hacking

Mobile platform attacks: Android, iOS and MDM

Hacking mobile platforms (CEH Module 17) is about how Android and iOS lock themselves down and what breaks the lock: rooting, jailbreaking, sideloading and weak device management. Learn which management model fits which owner as well; malware internals can wait.

Exam
312-50
Domain
7 of 9
Domain weight
10%
This file
~5%
Targets
17

The short list before you drill

  • Name the four places a mobile attack can land: the device, the network it rides on, the app, and the back-end server the app talks to
  • Explain sideloading and why it skips the store's review
  • Separate rooting (Android) from jailbreaking (iOS), and tethered from untethered jailbreaks
  • Match MDM, MAM and containerization to the ownership model each one suits
  • Recognize SMiShing and OTP hijacking as social engineering delivered to a phone
  • Name the edition: OWASP Top 10 Mobile Risks, 2024

Scope of the mobile module

Treat Module 17 as a vocabulary module with a thin layer of judgment. It shares Domain 7 (Mobile Platform, IoT, and OT Hacking, 10% in blueprint v5.0 as of Oct 11, 2026) with IoT and OT. Blueprint v5.0 lists mobile attack vectors, Android, iOS, MDM and security guidelines as sub-topics; the v13 course outline adds the OWASP Top 10 Mobile Risks 2024, SMiShing, OTP hijacking, rooting and jailbreaking.

Both platforms rest on the same two ideas. Each app runs in its own sandbox, and code has to be signed before the OS will trust it. Android layers a permission model on top that the user approves; iOS makes one curated store the normal install path. Learn those four facts cold. Full OS architecture diagrams return little for the hours they cost, so skim them once and stop.

Sideloading

Installing an app from outside the platform's store skips the store's review and signing checks. That is why managed devices block installs from unknown sources.

Defenses in the order they pay

Timely OS updates first: Android patches pass through each device maker, so an older handset can sit unpatched for a long time after a fix exists, while iOS updates come from one vendor. Then apps from the store only, a passcode policy enforced by management software, and a compliance check that keeps corporate data off any device that fails it.

When a test touches a phone the company does not own, the rules of engagement need the owner's agreement too.

Rooting and jailbreaking side by side

Two names for removing a platform's built-in restrictions
PointRootingJailbreaking
Platform (differs)AndroidiOS
What it removes (differs)Limits on superuser access to the operating systemApple's restrictions on unsigned code and protected system areas
Common precondition (differs)An unlocked bootloader on many devicesAn exploitable flaw in the installed iOS version
Effect on app isolationSandbox and permission guarantees stop holding for every appSandbox and permission guarantees stop holding for every app

Tinted rows marked ≠: the two differ.

Management and jailbreak terms

MDM
Mobile device management: controls the whole device, from enrollment and passcode policy to app inventory and remote lock or wipe.
MAM
Mobile application management: controls only the corporate apps and their data, which suits devices the company does not own.
Containerization
A separated workspace on the device for work apps and data. Removing it leaves personal content untouched.
BYOD, CYOD, COPE
Bring your own device, choose your own device from an approved list, corporate-owned personally enabled. Ownership decides how much control the company can claim.
Tethered jailbreak
Needs a computer connection at each boot to stay jailbroken. A semi-tethered one boots normally but loses the jailbreak until it is reapplied; an untethered one survives reboots by itself.

Mobile targets, notes included

On this module the option you nearly picked tells you more than the one you missed. After each answer, read that note first.

Answered 0/17Hits 0

T-01

During a static analysis of an Android application, you find an exported component with intent-filters handling external URIs but lacking permission attributes. Which vulnerability does this configuration introduce?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AModifying native libraries is about tampering with the app package itself, and an exported component's manifest settings have nothing to do with native library integrity.
  2. BAn exported component does not run shell commands by default; the exposure is that other apps can reach it, and any impact depends on what the component does with the input.
  3. CCorrect: an exported component without a permission requirement can be invoked by any app on the device, so access controls can be bypassed unless the component validates its callers and input.
  4. DA missing permission attribute does not stop an app from launching; newer Android versions only require exported components with intent filters to declare the exported value explicitly.
T-02

During mobile application testing, you encounter decompiled Java code utilizing a proprietary algorithm that outputs Base64-encoded blobs using a static hardcoded key. How should this implementation be classified?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: a homegrown algorithm with a key hardcoded in the app is insecure custom cryptography, because anyone who decompiles the app can recover the key, and Base64 is only an encoding.
  2. BAsymmetric encryption uses a public and private key pair from vetted algorithms, whereas a single static key in a proprietary scheme is neither standard nor asymmetric.
  3. CCompliant protection of data at rest relies on vetted algorithms and platform key stores such as Android Keystore, not a secret that ships inside the decompilable app binary.
  4. DDefense in depth adds independent layers of real protection, while a proprietary cipher with an exposed key gives little protection and can create a false sense of security.
T-03

Which type of Android rooting method will retain root access even after the device is rebooted?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APartial rooting is not a standard category of Android rooting, so it does not name a method that keeps root access across reboots.
  2. BAsynchronous rooting is not a recognized rooting type; the usual distinction is simply whether root access survives a restart of the device.
  3. CCorrect: permanent rooting changes the system so that root access persists after a reboot, which is why defenders and MDM tools treat it as a lasting compromise of device integrity.
  4. DTemporary rooting gives elevated access only until the device restarts, after which the device goes back to its normal unprivileged state.
T-04

Static analysis of an application reveals embedded native libraries, while dynamic traces show native functions executing immediately before unauthorized outbound network requests. Which conclusion is most appropriate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: native code that runs just before unauthorized outbound requests suggests the app is using a native layer to send data out, often to stay out of view of Java-level analysis.
  2. BEncryption performed in a native library would not explain why the requests are unauthorized, and the behavior the traces show points to data leaving the device, not to a protective measure.
  3. CMany legitimate apps ship native libraries for performance or graphics, so native code alone is not proof of malice; the evidence here is the correlated behavior, not the presence of native code.
  4. DOperating system telemetry comes from system services, not from native functions bundled inside a third-party application, so this explanation does not fit the observed traces.
T-05

Which of the following is NOT a layer in the iOS architecture?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: iOS runs on the XNU kernel, which comes from Darwin, not on a Linux kernel; a Linux kernel is the foundation of Android.
  2. BMedia is a real iOS layer that provides graphics, audio and video frameworks to the layers above it.
  3. CCocoa Touch is the top iOS layer, supplying the user interface frameworks and touch event handling that apps build on.
  4. DCore Services is a real iOS layer that provides basic system services such as networking, data management and iCloud access to the layers above it.
T-06

An iOS application's Info.plist file defines several exported custom URL schemes. Before classifying these schemes as a critical vulnerability, what subsequent verification step must an analyst perform?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AEntitlement signing concerns what capabilities the app may use, and correct signing does not show whether a URL scheme can be abused to reach sensitive data.
  2. BCorrect: a custom URL scheme is a normal deep-linking feature, and it becomes a real vulnerability only if untrusted input received through it can reach sensitive data or dangerous operations.
  3. CWhere the app was downloaded from does not change how its own URL scheme handlers process input, so the source of the download does not decide whether the vulnerability is real.
  4. DThird-party advertising frameworks raise separate privacy questions, but checking for them does not show whether the exported URL schemes can be exploited.
T-07

A telecommunications log snippet reveals unexpected MAP_SEND_ROUTING_INFO_FOR_SM requests originating from an external network. Which specific attack vector does this anomalous protocol activity indicate?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABaseband attacks target the phone's radio firmware and require physical proximity, while these requests come from an external network through carrier signaling.
  2. BMalware that steals contacts runs on the handset itself, whereas this log shows routing queries in the operator's core network, not activity on the device.
  3. CCorrect: unexpected SS7 routing-information requests for SMS from a foreign network are a classic sign of signaling-plane abuse, which carriers counter with SS7 firewalls and request filtering.
  4. DBrute-forcing a lock screen requires access to the device and would never show up as inter-carrier MAP signaling in a telecom log.
T-08

Which mobile operating system is most commonly targeted by malware attacks due to its open-source nature?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABlackBerry OS was a closed, proprietary platform with a small and shrinking user base, so it was never the main target of mobile malware.
  2. BiOS is closed source, allows sideloading only in limited ways and has a strictly controlled App Store, all of which narrow its malware attack surface compared with Android.
  3. CCorrect: Android's open-source code, huge market share, fragmented patching across vendors and support for third-party app stores make it the platform most targeted by mobile malware.
  4. DWindows Mobile has been discontinued and only ever had a small market share, so it was never the primary target of mobile malware.
T-09

Google's Android Enterprise is an example of which of the following systems for managing and securing mobile devices in a corporate environment?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABYOD is a policy that lets employees use personal devices, while Android Enterprise is the management technology that can enforce such a policy.
  2. BA VPN protects network traffic in transit, but it does not enroll devices, enforce policies or separate work profiles the way Android Enterprise does.
  3. CCorrect: Android Enterprise is Google's framework for mobile device management, supporting work profiles, policy enforcement and remote management through an MDM or EMM console.
  4. DA firewall filters network traffic by rules and has no part in enrolling, configuring or managing mobile devices.
T-10

An analyst notices a mobile device uploading massive amounts of data to a cloud service. Which additional telemetry source MUST be correlated to definitively flag this traffic as data exfiltration rather than a routine backup?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AProxy logs would confirm that the device connected to the cloud provider, but a legitimate backup goes to the same place, so they cannot tell the two cases apart.
  2. BFirmware patching logs explain changes to the operating system, not why an app suddenly uploaded large volumes of data, so they give no evidence of exfiltration.
  3. CSignature-based antivirus alerts often miss new or obfuscated malware, and having no alert says nothing about whether this upload was malicious.
  4. DCorrect: if an app gained access to contacts or location just before the upload spike, that context separates likely exfiltration from routine backup traffic.
T-11

What type of attack involves installing malicious applications on a mobile device by tricking users into believing they are installing legitimate apps?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA man-in-the-middle attack intercepts or alters traffic between two parties; it does not involve getting users to install a disguised application.
  2. BCorrect: repackaging means modifying a legitimate app to add malicious code and redistributing it, usually through third-party stores, so users think they installed the real app.
  3. CSmishing uses deceptive SMS messages to lure victims to links or reveal information; it may be how users are lured, but it does not describe a trojanized copy of a real app.
  4. DBluejacking means sending unsolicited messages to nearby devices over Bluetooth, which is mostly a nuisance and does not install any application.
T-12

During an Android malware analysis, an application triggers behavioral Runtime Application Self-Protection alerts but bypasses device-resident static signature scanning. Which technique is the malware MOST likely utilizing to evade detection?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA hardcoded key in the manifest is a static weakness that scanners can actually find, so it would not explain why the malware gets past static detection.
  2. BSending identifiers in cleartext is a privacy flaw that network monitoring can see, but it is not a way of hiding malicious code from static analysis.
  3. CAsking for excessive permissions is visible at install time and is often flagged by static review, so it does not explain why the scan came back clean.
  4. DCorrect: loading dex code at runtime keeps the malicious logic out of the installed package that static scanners inspect, while runtime monitoring such as RASP still sees the behavior.
T-13

What type of access does jailbreaking an iPhone provide?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ADomain admin is an Active Directory privilege level for Windows networks and has no meaning on a single iPhone.
  2. B"Low level root access" is not a recognized privilege tier, and jailbreaking gives the highest privilege on the device, not a reduced one.
  3. C"Priority level access" is not a real iOS privilege concept and does not describe what jailbreaking changes.
  4. DCorrect: jailbreaking removes Apple's restrictions and grants root-level privileged access, which also bypasses sandboxing and code-signing protections that enterprise security relies on.
T-14

A security team suspects an ongoing data exfiltration breach on a corporate mobile device. To minimize immediate damage, which action should the incident responder prioritize over preserving forensic evidence?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AReviewing installation logs is useful for later investigation, but it does nothing to stop data that is leaving the device right now.
  2. BCorrect: using MDM to cut the device off the network stops the exfiltration immediately, and doing this quickly to limit damage can take priority over preserving every piece of forensic evidence.
  3. CA thorough static analysis takes time and helps with root-cause work, but it does not contain an exfiltration that is still in progress.
  4. DInvolving law enforcement may be needed later, but escalating the incident does not stop data from leaving the device in the moment.
T-15

An employee at TechCorp asks if they can jailbreak their personal device under the company's BYOD policy. They are considering doing so with their own device. What would be the appropriate response?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: BYOD policies normally forbid jailbreaking, because a jailbroken device loses platform protections and cannot be trusted to meet the company's security baseline for accessing corporate data.
  2. BAllowing jailbreaking would let devices with weakened sandboxing and code-signing reach corporate resources, a risk most BYOD policies explicitly prohibit.
  3. CTwo-factor authentication protects logins, but it does not restore the integrity protections that jailbreaking removes from the device.
  4. DA VPN encrypts traffic in transit, but malware on a jailbroken device can still read corporate data before it is encrypted or after it arrives.
T-16

Which security mechanism is most effective for protecting sensitive data on mobile devices?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA screen lock controls casual access to the device, but without encryption the stored data can still be read by bypassing the operating system.
  2. BApp permissions limit which apps can reach which resources, but they do not protect stored data if the device itself is lost or examined offline.
  3. CRemote wipe works only after a loss is noticed and only if the device can still be reached, so it cannot guarantee protection of the data.
  4. DCorrect: full disk encryption keeps all stored data unreadable without the device credentials, so it stays protected even if the device is stolen or its storage is accessed directly.
T-17

Which mobile platform security feature helps prevent buffer overflow attacks?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACertificate pinning protects TLS connections against interception with forged certificates; it has nothing to do with memory corruption.
  2. BCorrect: ASLR randomizes where code and data sit in memory, so a buffer overflow becomes much harder to exploit reliably because target addresses are unpredictable.
  3. CApp sandboxing limits what a compromised app can access afterward, but it does not stop the overflow itself from being exploited inside that app.
  4. DCode signing checks that code comes from a trusted developer and has not been modified, but it does not prevent a memory bug in signed code from being exploited.

Mobile loose ends

Why does this module keep pointing at OWASP?

The v13 outline names the OWASP Top 10 Mobile Risks 2024 as its reference list (owasp.org, checked Oct 11, 2026). Know the edition year and recognize category names such as Improper Credential Usage and Inadequate Supply Chain Security; the rank order is low-yield.

Where does mobile overlap with IoT?

In the defenses more than the attacks: inventory every device, patch on a schedule, segment what you cannot patch. Domain 7 pairs the two modules, and the plant and sensor specifics live in the IoT and OT hacking module.

What does the mobile list add to the web Top 10?

It covers what lives on the device and inside the app package: how credentials are stored and used, the third-party SDKs pulled into the build, and how much of the app can be read back out of the binary. The server side the app talks to belongs to the web applications module.

Sources