EC-Council Certified Ethical Hacker (CEH) v12Mobile Platform, IoT, and OT HackingMedium

A mobile device management (MDM) solution is being deployed in an enterprise to secure corporate-owned Android and iOS devices. One of the primary requirements is to prevent users from installing applications from untrusted sources (e.g., third-party app stores or sideloaded APKs) to mitigate malware risks. Which MDM feature is specifically designed to enforce this policy?

  1. AVPN Configuration
  2. BApplication Whitelisting/Blacklisting
  3. CRemote Wipe
  4. DDevice Encryption Enforcement
Show answer & explanation

Correct answer: B. Application Whitelisting/Blacklisting

Application whitelisting (allowing only approved apps) or blacklisting (blocking specific apps/sources) is a core MDM feature used to control which applications can be installed on managed devices. This directly addresses the requirement of preventing installations from untrusted sources.

Why the other options are wrong

  • A. VPN Configuration secures network communication but doesn't manage app installation policies.
  • C. Remote Wipe erases device data and is used for lost/stolen devices, not for controlling app installations.
  • D. Device Encryption Enforcement ensures data at rest is encrypted but doesn't control app sources.

MDM App Control

Mobile Device Management (MDM) capabilities that allow organizations to control which applications can be installed, accessed, or run on managed mobile devices.

  • Includes app whitelisting (only approved apps allowed).
  • Includes app blacklisting (specific apps/sources blocked).
  • Mitigates risks from malware, unauthorized software, and data leakage.

Memory trick: MDM 'apps' control what runs, like a strict bouncer.

More Mobile Platform, IoT, and OT Hacking questions