What Mobile OS Modification Vulnerability Does an AUP Clause Prohibit?
A company is adding a clause to its AUP that states employees are not allowed to modify the operating system on mobile devices. Which of the following vulnerabilities is the organization addressing?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to map policy language about 'modifying the operating system' to the precise mobile threat category, while distinguishing OS-level exploitation from application-level installation methods.
This question evaluates how organizations use Acceptable Use Policies to mitigate mobile security risks by restricting OS-level changes. The community unanimously identifies jailbreaking as the correct match, emphasizing that prohibiting OS modification directly targets unauthorized privilege escalation and device tampering.
Candidates frequently select side loading because it involves installing unofficial apps on mobile devices, but sideloading does not require altering the underlying OS kernel or bypassing manufacturer restrictions, making it a classic distractor that ignores the question's specific wording.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Mobile OS Modification and Corporate Policy
Organizations deploy Acceptable Use Policies (AUPs) to standardize device configurations and prevent users from introducing unmanaged risk vectors. When an AUP explicitly forbids modifying the operating system, it targets techniques that strip away vendor-enforced security controls to grant elevated administrative access. In CompTIA terminology, this process is known as jailbreaking (iOS) or rooting (Android), both of which compromise the device's trusted execution environment.Why Jailbreaking is Correct
The decisive phrase in the scenario is 'modify the operating system.' Jailbreaking directly satisfies this condition by exploiting firmware vulnerabilities to remove sandboxing, disable signature verification, and unlock bootloader restrictions. As highlighted by community experts, CompTIA defines jailbreaking precisely as gaining full access to an iOS device by removing imposed limitations. By banning this practice, the organization preserves hardware/software integrity, enforces patch management, and prevents malicious actors from leveraging compromised kernels.Why Other Options Are Incorrect
- Cross-site scripting (XSS) and Buffer overflow are application-layer vulnerabilities completely unrelated to mobile OS configuration. XSS injects client-side scripts into vulnerable web pages, while buffer overflows exploit improper memory handling in software routines. Neither involves altering a device's operating system.
- Side loading refers to installing applications from untrusted sources outside the official app ecosystem. While sideloading can introduce malware, it operates at the application layer and does not require modifying the OS itself. Many test-takers confuse this with jailbreaking due to their shared association with mobile security, but the prompt's explicit focus on OS modification definitively rules out sideloading.
Official Reference
Exam Strategy
Always isolate the exact technical action described in the scenario before mapping it to an answer choice. If the prompt emphasizes 'modifying,' 'bypassing restrictions,' or 'gaining root access' on a mobile device, immediately eliminate application-layer attacks and focus exclusively on OS-level exploitation techniques like jailbreaking or rooting.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →