โ† All CMT Flashcard Decks

Security & Data Protection Standards Flashcards

7 cards from real CMT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Data Protection Standards flashcards as text
  1. Which type of attack involves an attacker intercepting communication between a mobile device and a Wi-Fi access point without either party knowing?

    Answer: Man-in-the-middle (MitM) attack

    A man-in-the-middle attack intercepts and potentially alters communications between two parties who believe they are communicating directly.

  2. A customer reports their device was stolen. They want to prevent the thief from reselling it. Which feature specifically ties a device to an account and blocks activation on a new account?

    Answer: Activation Lock (Find My / FRP)

    Activation Lock on iOS and Factory Reset Protection (FRP) on Android prevent a device from being set up under a new account without the original owner's credentials.

  3. What is the purpose of certificate pinning in a mobile application?

    Answer: To prevent MitM attacks by validating the server's specific certificate

    Certificate pinning ensures the app only trusts a specific known certificate, preventing attackers from using a rogue but technically valid certificate to intercept traffic.

  4. Which of the following BEST describes 'jailbreaking' a mobile device from a security standpoint?

    Answer: Bypassing OS security restrictions to allow unauthorized code execution

    Jailbreaking removes OS-level security sandboxing, exposing the device to malware and unauthorized access that the stock OS would normally block.

  5. A shop receives a device for liquid damage repair that contains sensitive health data. Under HIPAA, what obligation does the repair shop have?

    Answer: The shop must sign a Business Associate Agreement (BAA) and handle data appropriately

    Repair shops that handle devices containing protected health information (PHI) may qualify as business associates and must execute a BAA and follow HIPAA safeguards.

  6. Which app permission model approach is considered MOST secure for a mobile device?

    Answer: Prompt the user for each permission at the time it is needed (runtime permissions)

    Runtime permissions give users contextual control over what data an app can access exactly when it needs it, reducing unnecessary data exposure.

  7. What is the role of a Trusted Execution Environment (TEE) in mobile device security?

    Answer: It provides an isolated, hardware-backed environment for processing sensitive data like biometrics and cryptographic keys

    A TEE (e.g., ARM TrustZone) runs in a separate, hardware-isolated zone that protects sensitive operations even if the main OS is compromised.