WGU C844 EXAM PREP: QUESTIONS AND
ANSWERS 2026 FINAL PAPER.
⫸ What is data leakage? Answer: A term used to describe company
data leaving the traditional network boundaries
⫸ What is the difference between Mobile Device Management
(MDM) and Mobile Application Management (MAM)? Answer: The
system that IT uses to provide, configure, and manage mobile devices
in the workplace is mobile device management (MDM). Whereas
MDM is device oriented, mobile application management (MAM) is
used to manage application software on mobile devices. MDM and
MAM are considered subsets of enterprise mobility management
(EMM).
⫸ What is Enterprise Mobility Management (EMM)? Answer: It is a
framework that consists of sets of people, processes and technologies
required to manage mobile IT within the enterprise.
⫸ The practice of requiring users to download applications only
from an approved portal or source is known by what term? Answer:
The correct answer is Application Provenance.
This is a requirement to only download applications from approved
portals or known sources.
,⫸ What are phalbets? Answer: Devices that are somewhere between
a phone and a tablet
⫸ What is a premium SMS? Answer: is a pay-as-you-go service
available on smartphones. Charges can be linked directly to a credit
card or tacked onto the monthly bill. Hackers often take advantage of
this service, using malware to initiate premium SMS messages from
hacked phones back to services that they own or control or from
which they can otherwise extract payment. Cybercriminals love
premium SMS because it allows them to quickly monetize their
efforts.
⫸ What is clickjacking? Answer: The purpose of this exploit is to
confuse the victim by creating a webpage with a background of
invisible frames. The attacker then superimposes another set of frames
or buttons that the victim can see. If the victim clicks on a frame
button once or twice and nothing happens, they will tend to swipe the
mouse around, clicking indiscriminately, hence triggering the exploit.
⫸ What is likejacking? Answer: likejacking exploit is usually very
successful on smartphones due to their smaller screens, which are
more difficult to see. In this case, an invisible frame or button is
placed directly on top of a Facebook Like button. Clicking the button
works as normal but also infects the device.
⫸ What are the stages of pentesting smartphones? Answer:
Pentesting smartphones involves the following stages:
Recon —During this stage, the tester gathers information by
identifying the types of mobile devices on the target network.
, Scanning —After the types of phones have been identified, the
scanning phase can proceed. When scanning for mobile devcies, the
tester looks to identify networks sought out by mobile devices.
Exploitation - In the exploitation stage, the tester actually captures
and gains control of the mobile device.
Post-Exploitation - During the post-exploitation stage, the tester
inspects the phone for sensitive data in common areas such as notes as
well as SMS and browser history databases. The tester might also
search the device for stored passwords in the keychain or payloads as
a backdoor, dependong o the scope of the project.
⫸ What are the Top 10 Mobile Controls? Answer: 1. Protect
sensitive data on the mobile device.
2. Handle password credentials securely
3. Ensure sensitive data is protected during transit
4. Implement correct authentication, authorization, and session
management.
5. Keep the backend APIs and platform secure
ANSWERS 2026 FINAL PAPER.
⫸ What is data leakage? Answer: A term used to describe company
data leaving the traditional network boundaries
⫸ What is the difference between Mobile Device Management
(MDM) and Mobile Application Management (MAM)? Answer: The
system that IT uses to provide, configure, and manage mobile devices
in the workplace is mobile device management (MDM). Whereas
MDM is device oriented, mobile application management (MAM) is
used to manage application software on mobile devices. MDM and
MAM are considered subsets of enterprise mobility management
(EMM).
⫸ What is Enterprise Mobility Management (EMM)? Answer: It is a
framework that consists of sets of people, processes and technologies
required to manage mobile IT within the enterprise.
⫸ The practice of requiring users to download applications only
from an approved portal or source is known by what term? Answer:
The correct answer is Application Provenance.
This is a requirement to only download applications from approved
portals or known sources.
,⫸ What are phalbets? Answer: Devices that are somewhere between
a phone and a tablet
⫸ What is a premium SMS? Answer: is a pay-as-you-go service
available on smartphones. Charges can be linked directly to a credit
card or tacked onto the monthly bill. Hackers often take advantage of
this service, using malware to initiate premium SMS messages from
hacked phones back to services that they own or control or from
which they can otherwise extract payment. Cybercriminals love
premium SMS because it allows them to quickly monetize their
efforts.
⫸ What is clickjacking? Answer: The purpose of this exploit is to
confuse the victim by creating a webpage with a background of
invisible frames. The attacker then superimposes another set of frames
or buttons that the victim can see. If the victim clicks on a frame
button once or twice and nothing happens, they will tend to swipe the
mouse around, clicking indiscriminately, hence triggering the exploit.
⫸ What is likejacking? Answer: likejacking exploit is usually very
successful on smartphones due to their smaller screens, which are
more difficult to see. In this case, an invisible frame or button is
placed directly on top of a Facebook Like button. Clicking the button
works as normal but also infects the device.
⫸ What are the stages of pentesting smartphones? Answer:
Pentesting smartphones involves the following stages:
Recon —During this stage, the tester gathers information by
identifying the types of mobile devices on the target network.
, Scanning —After the types of phones have been identified, the
scanning phase can proceed. When scanning for mobile devcies, the
tester looks to identify networks sought out by mobile devices.
Exploitation - In the exploitation stage, the tester actually captures
and gains control of the mobile device.
Post-Exploitation - During the post-exploitation stage, the tester
inspects the phone for sensitive data in common areas such as notes as
well as SMS and browser history databases. The tester might also
search the device for stored passwords in the keychain or payloads as
a backdoor, dependong o the scope of the project.
⫸ What are the Top 10 Mobile Controls? Answer: 1. Protect
sensitive data on the mobile device.
2. Handle password credentials securely
3. Ensure sensitive data is protected during transit
4. Implement correct authentication, authorization, and session
management.
5. Keep the backend APIs and platform secure