Sy0 601 13
Sy0 601 13
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 2
Syllabus Objectives Covered
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 3
Mobile Device Deployment Models
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 4
Enterprise Mobility Management
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 5
iOS in the Enterprise
• App development
• Software Development Kit
(macOS only)
• App Store
• Device Enrollment Program
• Volume Purchase Program
• Developer Enterprise Program
• iOS vulnerabilities and patch
management
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 6
Android in the Enterprise
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 7
Mobile Access Control Systems
• Smartphone authentication
• Password
• PIN
• Swipe pattern
• Biometric
• Screen lock
• Context-aware authentication
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 8
Remote Wipe
• “Kill switch”
• Sets device to factory defaults or
clears storage (or storage
segment)
• Initiated from enterprise
management software
• Thief might be able to keep device
from receiving the wipe command
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 9
Full Device Encryption and External Media
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 10
Location Services
• Geolocation
• Location Services
• Global Positioning System (GPS)
• Indoor Positioning Systems (IPS)
• Geofencing to apply location-
based policies automatically
• Disable on-board camera/video
through MDM/EMM controls
• GPS tagging
• Risks to personal information Android is a trademark of Google LLC.
• Track movements (assist social
engineering)
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 11
Application Management
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 12
Content Management
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 13
Rooting and Jailbreaking
• Rooting
• Principally Android
• Custom firmware/ROM
• Jailbreaking
• Principally iOS
• Patched kernel
• Tethered jailbreak
• Carrier unlocking
• Risks to enterprise management
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 14
Topic 13B
Implement Secure Mobile Device Connections
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 15
Syllabus Objectives Covered
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 16
Cellular and GPS Connection Methods
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 17
Wi-Fi and Tethering Connection Methods
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 18
Bluetooth Connection Methods
• Device discovery
• Authentication and authorization
• Pairing mechanism
• Malware and exploits
• Bluebourne
• Bluejacking
• Bluesnarfing
• Rogue firmware peripheral devices
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 19
Infrared and RFID Connection Methods
• Infrared
• IR blaster
• IR sensor
• Radio Frequency ID (RFID)
• (Usually) unpowered tags
• Transmit when in range of reader
• Skimming attack
• Encrypt sensitive information
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 20
Near Field Communications and Mobile Payment
Services
• Near Field Communications (NFC)
• Connection configuration/bump
• Mobile wallet apps
• Eavesdropping/skimming
• Denial of service
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 21
USB Connection Methods
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 22
SMS/MMS/RCS and Push Notifications
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 23
Firmware Over-the-Air Updates
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 24
Microwave Radio Connection Methods
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 25
Lesson 13
Summary
CompTIA Security+ Lesson 13 | Copyright © 2020 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org 26