SRM Institute of Science and Technology
College of Engineering and Technology
School of Computing
Department of Networking and Communications
Academic Year: 2025-26 (ODD)
SET- D
Test: FT2 Date: 15-09-2025
Course Code & Title: 21CSE489T- MOBILE AND WIRELESS SECURITY Duration: 100 minutes
Year & Sem: IV Year / VII Sem Max. Marks: 50
Course Articulation Matrix:
[Link] Course PO PO PO PO PO PO PO PO PO PO PO PO PO PO PO
. Outcom 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
e
1 CO1 2 - 3 - 3 - - - - - - - - - -
2 CO2 - - 3 - - - - - - - - - - - -
3 CO3 2 - 3 - - - - - - - - - - - 3
4 CO4 - - 3 - 3 - - - - - - - - - 3
5 CO5 - - - - 3 - - - - - - - - - -
Part – A: (10 x 1 = 10 Marks)
Instructions: Answer all Questions
Q. Question Marks BL CO PO PI
No Code
1 In Mobile IP, which mechanism is used to ensure 1 L1 1 1,3, 1.7.1
seamless mobility and maintain ongoing sessions? 5
A) Location update with Home Agent and Foreign Agent
tunneling
B) Dynamic IP assignment through DHCP only
C) Layer 2 handoff without IP-level coordination
D) Broadcast flooding to locate mobile nodes
2 What technique is commonly used to defend against 1 L2 1 1,3, 2.5.3
jamming attacks in cellular networks? 5
A) Increasing transmission power only
B) Frequency hopping and spread spectrum techniques
C) Static frequency allocation
D) Using fixed IP addresses
3 Why are wireless channels considered more vulnerable 1 L1 1 1,3, 1.5.1
to eavesdropping compared to wired channels? 5
A) Wireless signals can propagate beyond physical
boundaries
B) Wired channels use only analog signals
C) Wireless channels cannot use encryption
D) Wired networks have no physical security
4 What is a major disadvantage of relying solely on 1 L2 1 1,3, 2.5.2
application-layer security in mobile apps? 5
A) Lack of defense against network-layer attacks such as
DoS or jamming
B) Inability to secure user credentials
C) Requirement for complex hardware
D) Prevents user authentication
5 What is a common security vulnerability introduced by 1 L2 1 1,3, 2.5.1
the use of multiple access technologies (e.g., Wi-Fi, LTE, 5
5G) on a single mobile device?
A) Attackers can exploit the weakest link among networks
to compromise overall device security
B) Device battery life improves
C) Increased bandwidth guarantees security
D) Single-point encryption across all networks
6 Which of the following best describes the primary 1 L1 2 3 1.7.1
security improvement introduced in 3G networks over
2G?
A) Use of asymmetric cryptography for authentication
B) Mutual authentication between subscriber and network
C) Lack of encryption for user data
D) Open authentication protocol without key exchange
7 The key objective of the IEEE 802.21 standard is to: 1 L1 2 3 1.7.1
A) Provide efficient power management for mobile devices
B) Enable handover between heterogeneous networks at
layer 2 and layer 3
C) Improve error correction in wireless transmissions
D) Define new encryption standards for WLAN
8 Which attack specifically targets the key derivation 1 L2 2 3 2.5.3
process in 4G LTE AKA (Authentication and Key
Agreement)?
A) Key reinstallation attack
B) Downgrade attack forcing 2G fallback
C) Eavesdropping on RRC messages
D) Replay attack exploiting sequence numbers
9 Which threat is specifically targeted by application-level 1 L1 2 3 1.7.1
sandboxing on mobile devices?
A) Unauthorized resource access by rogue applications
B) Network eavesdropping
C) Man-in-the-middle attacks on cellular networks
D) Physical device theft
10 Which of the following describes the key agreement in 1 L2 2 3 1.7.1
LTE AKA protocol?
A) Mutual authentication using pre-shared keys only
B) Use of challenge-response with sequence numbers and
key derivation based on shared secrets stored in SIM and
HSS
C) Open key exchange without authentication
D) Use of static keys for all sessions
Part – B: (4 x 5 = 20 Marks)
Instructions: Answer any 4 Questions
Describe the main features and differences among the IEEE
802.11, 802.15, 802.16, 802.20, and 802.21 standards. How
1,3,
11 do these standards support different wireless 5 L2 1
5
1.7.1
communication needs?
How do security requirements in mobile and wireless
communications differ from traditional wired
1,3,
12 communications? Identify key security principles that must 5 L2 1
5
1.7.1
be addressed in mobile environments
Evaluate the advantages and disadvantages of implementing
application-level security in mobile communications. When
1,3,
13 is it preferable to rely on application-level security versus 5 L4 1
5
2.6.4
network-level security?
Explain the roles of authentication and authorization in
maintaining cybersecurity. How do these mechanisms differ
14 5 L3 2 3 1.7.1
and complement each other?
Describe the Incident Response Process and its importance
in managing cybersecurity breaches in mobile
15 5 L3 2 3 4.4.1
environments.
Outline the key components of Android architecture and its
security model. How does the Android security model
16 5 L3 2 3 1.7.1
protect against common threats?
Part – C: (2 x 10 = 20 Marks)
Instructions: Either or Choice Type Questions
15(a) A mobile app development company has launched a new 10 L3 1 1,3, 2.6.3
app for Android devices. However, users report that their 5
devices experience unusual battery drain and data usage,
raising concerns about app security and privacy.
(a) Identify potential security risks associated with mobile
applications on Android platforms. [4 Marks]
(b) Explain how Android’s security model can help mitigate
these risks. Suggest best practices for developers to ensure
application-level security and protect user data.
Additionally, discuss the security implications if a device is
rooted. [6 Marks]
OR
15(b) A mobile carrier is transitioning from legacy GSM/GPRS 10 L4 1 1,3, 2.5.1
infrastructure to a 5G network. Customers demand high- 5
speed connectivity and robust security for mobile internet
and IoT applications. However, concerns about privacy and
data protection remain.
(a) Discuss the key security improvements introduced by
5G compared to GSM and GPRS. [4 Marks]
(b) How does 5G architecture address privacy and security
concerns inherent in earlier generations? Additionally,
analyze potential new security risks introduced by 5G and
recommend mitigation strategies to ensure secure mobile
communication. [6 Marks]
16(a) An organization plans to launch a secure communication 10 L5 2 3 2.7.1
app for both Android and iOS platforms. The app will
handle sensitive voice and messaging data, and must be
resistant to interception and unauthorized access.
(a) Compare the security architectures of Android and
iOS. How do both platforms handle application
sandboxing, permissions, and traffic interception
protection? [4 Marks]
(b) Evaluate which platform provides stronger default
security and discuss best practices for securing cross-
platform mobile apps. [6 Marks]
OR
16(b) A user complains that after rooting their Android phone, 10 L5 2 3 2.5.3
several apps started crashing, and some personal data was
compromised. On inspection, it was found that malware had
gained root access and intercepted sensitive
communications.
Explain the Android security model and how it protects
users under normal (non-rooted) conditions. What are the
security implications of rooting a device? Describe how
rooted devices bypass system protections and suggest
mitigation techniques developers or enterprises can use to
secure apps on rooted devices
Course Outcome (CO) and Bloom’s level (BL) Coverage in Questions
CO Coverage in %
30
25 25
25
20
15
10
5
0
CO 1 CO2 CO3 CO4 CO5 L1 L2 L3 L4 L5
Approved by the Audit Professor/Course Coordinator