220-1102 - Software Troubleshooting (22% of the exam) - Section 3.5

Troubleshoot mobile OS and application security issues.

Identify mobile security symptoms - high resource use, sluggish response, abnormal data or battery drain, unexpected app permissions, leaked personal files, and unauthorised account or location access - and link them to likely causes such as a malicious app, a compromised account, or a jailbroken or rooted device. Choose the correct response, including reviewing app permissions, uninstalling suspicious apps, updating the OS, enabling MDM controls, and performing a factory reset where compromise is confirmed.

Mobile securityApp permissionsRooting / jailbreakingData leakageMDM

Practice question for this objective

Free sampleSoftware Troubleshootinghard

Priya reports that her Android phone exhausts its monthly mobile data allowance within days of installing a free QR-scanner app, and the app has been granted access to contacts, location and SMS. Which action BEST addresses the likely data leakage while keeping the phone usable?

  • AReview and revoke the QR-scanner app's unneeded permissions, and uninstall it if the behaviour continues. Correct
  • BEnable a data-saver mode that caps background mobile data for every installed app on the phone.
  • CPerform a full factory reset to remove any hidden components the app may have installed.
  • DDisable mobile data entirely and rely only on Wi-Fi until the data allowance renews next month.
Excessive app permissions are the usual cause of mobile data leakage, so revoking unnecessary permissions and removing the app addresses the root cause. Data leakage on mobile most often results from apps granted permissions far beyond their function; the fix targets the permission grant itself rather than throttling the network or wiping the device.

Why A is correct: A scanner needs only the camera, so contacts, location and SMS access is excessive; revoking those permissions stops the leakage, and removing the app eliminates the cause if it persists.

Why B is wrong: Capping background data can reduce usage, so it looks helpful, but it treats the symptom and leaves an over-permissioned app free to harvest and exfiltrate contacts and location.

Why C is wrong: A reset would clear the app, but it is disproportionate for a single over-permissioned application and destroys unrelated user data before less drastic measures are tried.

Why D is wrong: Switching to Wi-Fi hides the billing symptom but the app keeps collecting and sending personal data over any connection, so the underlying leakage is unresolved.

See more 220-1102 practice questions, answers explained.

Exam traps in Software Troubleshooting

Answers that look right on this material and are not. Each one is a distractor from a different question in the 220-1102 bank for this domain.

  • A user deliberately factory-resets a handset before selling it, overwriting personal data with the device's built-in secure erase so nothing is recoverable.

    Why it is wrong: Tempting because it involves personal data, but a deliberate secure erase is proper sanitisation for reuse, not an unauthorised exposure of information.

  • A recently cleared application cache that forces temporary files to be rebuilt a single time.

    Why it is wrong: Rebuilding a cache once is a brief, minor cost and does not account for the sustained drain the question describes.

  • Enable airplane mode so that the pop-up adverts can no longer appear on the screen

    Why it is wrong: Airplane mode may hide network-driven pop-ups, but it only masks the symptom, blocks legitimate use, and leaves the offending app installed and active on the device.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.