🏠 Back to Exam Syllabus 📺 RooCloud on YouTube 🎯 Free CISSP Practice Test

CISSP 9.18 - Mobile Devices (Part 2 of 3)

This episode of the ISC2 Certified Information Systems Security Professional (CISSP) exam prep series continues the Domain 3 tour of mobile security, moving into location, content, and apps — the management controls that keep mobile devices in line, and what happens when users try to reshape their devices in ways that quietly tear down the guardrails you put in place.

What this episode covers

Watch the full episode above for the worked examples and detailed explanations of each concept.

Frequently Asked Questions

How else can a mobile device be located beyond GPS?

Wi-Fi positioning uses the known spots of nearby access points to place a device indoors, cell tower triangulation locates a phone through the mast network, and Bluetooth beacons can track a device by its wireless address. Even motion and environmental sensors or the camera and microphone can help pin down location. Geofencing then draws a virtual boundary that automatically switches features on or off, like disabling a camera the moment a device enters a secure site.

How do you govern which apps run on a mobile device?

Application control limits what can be installed, forces required apps, and locks down settings for compliance, usually enforced through device management. The strongest posture is allow listing, sometimes called deny by default, where nothing runs unless it is on a preapproved list, so even unknown malware is blocked. Deny listing is looser, permitting everything except items you specifically ban, and mobile application management governs just the apps rather than the whole device.

What risks hide in push notifications and third-party app stores?

Attackers use push notifications for social engineering and malicious links, and a push locker can trap a user in an endless loop of prompts until they close the browser entirely. Third-party app stores are riskier still, because they screen apps far less carefully than the official stores. On many devices a single setting to allow unknown sources opens the floodgates, which is why managed devices usually block outside stores altogether.

What happens when users root, sideload, or reflash their devices?

Rooting, called jailbreaking on Apple devices, breaks the built-in restrictions to gain full system control, which also means any malicious code now runs with those same total privileges. Sideloading installs apps by hand from outside the store, bypassing the safeguards your management enforces, and custom firmware replaces the stock operating system entirely, where a botched attempt can leave a device bricked. Carrier unlocking is the tame exception, and organizations should block modified devices from company resources.

Why manage firmware updates over the air?

Over-the-air firmware updates arrive by carrier or Wi-Fi, and owners should generally install them to stay patched. Yet an update can change configuration or clash with your management controls, so for managed devices you test first and may hold a device back until your management tools support the new version. Your standard patch, configuration, and change management discipline applies here too.

📚 Master the ISC2 CISSP Exam!

Reinforce this lesson with real practice. The RooCloud CISSP Practice Pack gives you 6,000+ exam-style questions, 366 section-wise practice tests and 40 full-length adaptive (CAT) tests across all 8 CISSP domains, with full explanations. Start with a FREE full-length adaptive CISSP test →


Reference: This article is based on concepts discussed in CISSP 9.18 - Mobile Devices (Part 2 of 3).