🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 27 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

During an internal penetration test you discover that the company's MobileIron server is running in an "open enrollment" mode for Android: any handset that browses to the public enrollment URL and supplies a valid corporate e-mail address immediately receives the full Mobile Device Management profile. What is the primary security risk introduced by this configuration flaw?

  • An attacker can disable Google Play Protect on enrolled devices and silently install apps from the public Play Store.

  • An attacker can trigger CVE-2019-2215 on all enrolled devices to gain kernel-level root without further user interaction.

  • An attacker can remotely brute-force the screen-lock PIN of already-enrolled devices through the MDM console.

  • An attacker can enroll a personal device and automatically obtain enterprise Wi-Fi, VPN, and application configurations, giving unauthorized network access.

Certified Ethical Hacker (CEH)
Mobile Platform, IoT, and OT Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot