EnsurePass
2018 Mar CompTIA Official New Released ADR-001
100% Free Download! 100% Pass Guaranteed!
http://www.EnsurePass.com/ADR-001.html
CompTIA Mobile App Security Certification Exam (Android Edition)
Question No: 21
Session keys are useful because:
-
they temporarily provide a mechanism to maintain the state of user interaction.
-
they are generated on the Android device locally upon startup.
-
there is only one key to generate.
-
they are more secure than public/private keys.
Answer: A
Question No: 22
An app accessing protected APIs should use which manifest declaration?
-
app-permissions
-
add-permissions
-
grant-permission
-
uses-permission
Answer: D
Question No: 23
Which of the following describes a security risk that may have to be accepted when using a commercial cross-platform mobile application framework?
-
Allowing code to run outside the app sandbox
-
Installing HTML 5 support on user device
-
Digest authentication without HTTPS
-
Using native code libraries without source code review
Answer: D
Question No: 24
Which of the following is an effective means of confirming data integrity?
-
File access control
-
Set the No execute (NX) bit on data segment in memory
-
Base64 encoding
-
Digital signatures
Answer: D
Question No: 25
Which of the following describes the purpose of the HTTPOnly cookie attribute?
-
This attribute ensures that such cookies are only sent over HTTP connections and not over SSL making them unusable.
-
This attribute requests that clients use the cookie only for HTTP connections and not expose it to client-side scripting.
-
This attribute requests that other protocols cannot access such cookies.
-
This attribute ensures that such cookies are only transmitted over an encrypted connection.
Answer: B
Question No: 26
Android’s kernel-level app sandbox provides security by:
-
assigning a unique user ID (UID) to each app and running in a separate process.
-
running all apps under an unprivileged group ID (GID).
-
restricting read access to an app’s package to the kernel process.
-
preventing an app’s data files from being read by any running process.
Answer: A
Question No: 27
Which of the following defines the difference between static and dynamic analysis of an application?
-
Static analysis can be used against encrypted code and is able to determine the actual instructions running on a device, while dynamic analysis is easily fooled when code is encrypted.
-
Static analysis consists of examining an application’s code as it is provided, while dynamic analysis consists of examining the application as it runs on an emulator or other debugging environment.
-
Static analysis is focused solely on the recovery of string and hardcoded values while
dynamic analysis aims to understand the function of the code itself.
-
Static analysis requires a dataflow-modeling tool to examine all data paths, while dynamic analysis can be conducted using only an Android device.
Answer: B
Question No: 28
Which of the following statements is TRUE about session tokens?
-
Session tokens should be unpredictable and be short to derive a maximum security benefit with minimal storage.
-
Session tokens should be reused every time a particular user logs in.
-
Session tokens should be an obfuscated or encrypted version of the user’s ID.
-
Session tokens should be unpredictable, of sufficient length and contain no information about the user.
Answer: D
Question No: 29
Why are file permissions important to security?
-
They prevent files from being transmitted to another device.
-
They hide files in the file system.
-
They provide links to files outside the sandbox.
-
They determine which processes can read files.
Answer: D
Question No: 30
On an unencrypted rooted Android device, which of the following BEST describes which data is recoverable?
-
Active data and some deleted data.
-
Active data and none of the deleted data.
-
Only some active data and no deleted data.
-
Only some active data and some deleted data.
Answer: A
100% Free Download!
–Download Free Demo:ADR-001 Demo PDF
100% Pass Guaranteed!
–Download 2018 EnsurePass ADR-001 Full Exam PDF and VCE
EnsurePass | ExamCollection | Testking | |
---|---|---|---|
Lowest Price Guarantee | Yes | No | No |
Up-to-Dated | Yes | No | No |
Real Questions | Yes | No | No |
Explanation | Yes | No | No |
PDF VCE | Yes | No | No |
Free VCE Simulator | Yes | No | No |
Instant Download | Yes | No | No |
2018 EnsurePass IT Certification PDF and VCE
100-105 Dumps VCE PDF
200-105 Dumps VCE PDF
300-101 Dumps VCE PDF
300-115 Dumps VCE PDF
300-135 Dumps VCE PDF
300-320 Dumps VCE PDF
400-101 Dumps VCE PDF
640-911 Dumps VCE PDF
640-916 Dumps VCE PDF
70-410 Dumps VCE PDF
70-411 Dumps VCE PDF
70-412 Dumps VCE PDF
70-413 Dumps VCE PDF
70-414 Dumps VCE PDF
70-417 Dumps VCE PDF
70-461 Dumps VCE PDF
70-462 Dumps VCE PDF
70-463 Dumps VCE PDF
70-464 Dumps VCE PDF
70-465 Dumps VCE PDF
70-480 Dumps VCE PDF
70-483 Dumps VCE PDF
70-486 Dumps VCE PDF
70-487 Dumps VCE PDF
220-901 Dumps VCE PDF
220-902 Dumps VCE PDF
N10-006 Dumps VCE PDF
SY0-401 Dumps VCE PDF