GIAC GMOB Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Mobile Device Security Analyst |
| Exam Number: | GMOB |
| Related Certifications: | GIAC Security Essentials (GSEC) GIAC Penetration Tester (GPEN) |
| Exam Price: | $999 USD |
| Available Languages: | English |
| Exam Duration: | 120 minutes |
| Passing Score: | 71% |
| Certificate Validity Period: | 4 years |
| Real Exam Qty: | 75 |
| Exam Format: | Open-book (hardcopy materials only), Multiple choice, Proctored |
| Recommended Training: | SANS SEC575: Mobile Device Security and Ethical Hacking |
| Exam Registration: | GIAC Official Registration Pearson VUE Scheduling |
| Sample Questions: | GIAC GMOB Sample Questions |
| Exam Way: | Web-based, proctored remotely via ProctorU or onsite at Pearson VUE centers |
| Pre Condition: | No formal prerequisites; recommended experience in mobile security or completion of SANS SEC575 training |
| Official Syllabus URL: | https://www.giac.org/certifications/mobile-device-security-analyst-gmob |
GIAC GMOB Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Mitigating Mobile Threats | - Mobile malware protection and response - Data protection for lost or stolen devices |
| Topic 2: Manipulating Mobile Application Behavior | - Security evasion techniques - Modifying application logic and configuration |
| Topic 3: Analyzing Mobile Applications | - Static and dynamic analysis techniques - Detect potentially harmful behavior - Evaluate application binaries and permissions |
| Topic 4: Mobile Application Security Assessment | - Audit and validation methods - Use of MASVS standard |
| Topic 5: Managing iOS Devices and Applications | - Jailbreaking and security implications - Data structures and application security - iOS configuration and security models |
| Topic 6: Manipulating Network Traffic | - Attack encrypted traffic (SSL/TLS) - Capture and intercept mobile network traffic |
| Topic 7: Managing Android Devices and Applications | - Rooting and security implications - Data structures and application security - Android configuration and security models |
| Topic 8: Reverse Engineering Mobile Applications | - Core concepts and tools - Binary analysis and code inspection |
GIAC Mobile Device Security Analyst Sample Questions:
Question 1
What aspect of Android configuration is crucial for understanding its security posture?
Response:
A. Bluetooth visibility settings
B. Permission model and its enforcement
C. Screen timeout settings
D. Wallpaper and theme preferences
Question 2
Which feature is critical for protecting data on a device that is lost or stolen?
Response:
A. Personalized ringtones
B. Multi-factor authentication
C. GPS tracking
D. Device encryption
Question 3
How can reverse engineering contribute to improving mobile application security?
Response:
A. By identifying and fixing security flaws
B. By simplifying the app's code
C. By facilitating the removal of essential security features
D. By allowing unrestricted access to app data
Question 4
What can be used to understand and alter the behavior of iOS applications by manipulating their method calls?
Response:
A. Ruby
B. Swift
C. C#
D. Cycript
Question 5
Which tool is commonly used to modify the runtime behavior of Android applications for security testing?
Response:
A. Selenium
B. Eclipse
C. Android Studio
D. Xposed Framework
Solutions:
| Question 1 Answer: B | Question 2 Answer: D | Question 3 Answer: A | Question 4 Answer: D | Question 5 Answer: D |
We're so confident of our products that we provide no hassle product exchange.


By Evan

