comptia mobile app security, it certification exams

CompTIA Mobile App Security+: what you need to know about the new ADR-001 and IOS-001 exams

  • By
  • November 8, 2013
1 Comment

comptia mobile app security, it certification examsAs we mentioned the other day, CompTIA recently introduced two interesting certifications. So, if you are working towards the career of mobile apps developer or a cloud professional, consider that you have gotten another goal to strive to.

Today, we’re talking about the vendor’s Mobile App Security+ Certification. With this addition, CompTIA raises an important issue, so often ignored: the security of mobile apps. As we all know (or at least have a gut feeling about), unless we’re talking big players’ ecommerce apps, healthcare and finance, the apps we play around with on our smartphones, aren’t too secure, right?

With smartphones being so vulnerable to hacking, theft or loss, CompTIA insists that it’s the developer’s responsibility to secure the application. And the only sure way to do that lies in planning for security and building security features from the very first stages of the app development process. The challenges of mobile app security can be overcome with the latest technology, such as HTML5, CSS3, JQuery, JQuery Mobile.

So, as CompTIA is fighting to step up security standards of mobile app development, we can expect their certification to become the big thing employers will be looking for in the resumes of their potential developers. So, you should prepare for it. And, as usual, there is no better time than now.

CompTIA Mobile App Security+ has two editions of the exam – for Android and iOS mobile apps (exams ADR-001 and IOS-001 respectively). The exams include 100 multiple choice questions. There is no confirmed information as to whether there are going to be exams for other platforms (Windows Phone mainly, given its steady growth this year), so if Windows is your platform of choice, Microsoft is still your go-to certification destination.

The exams (ADR-001 and IOS-001) will certify that the candidate has the knowledge and skills required to create a secure native Android/iOS mobile application, including securing network communications, backend Web services, etc. Both exams are suited for professionals with at least 2 years of mobile app development experience. Candidates need to be familiar with the principles of secure application development, iOS/Android SDK, and Java(for Android developers).

According to CompTIA, Mobile App Security+ Certification Exam (iOS Edition) IOS-001 covers the following domains:

  1. Application Security and SDLC Fundamentals
  2. Objective-C Coding
  3. iOS SDK, APIs, and Security Features
  4. Web Service and Network Security
  5. Data Security and Implementing Encryption
  6. Application Hardening

To pass, you should have the knowledge and skills to:

  • Describe fundamental principles of application security
  • Describe the security model of iOS devices
  • Describe common threats to mobile application security
  • Develop moderately complex applications using the iOS SDK
  • Describe Web services security model and vulnerabilities
  • Properly implement SSL/TLS for Web communications
  • Utilize the security features of the iOS operating system and APIs
  • Properly implement secure coding techniques
  • Avoid insecure retention of data in memory
  • Describe common implementations of cryptography such as PKI
  • Leverage encryption for storage and/or communications
  • Harden an application against attack to levels appropriate for the risk model of the
  • Application

CompTIA Mobile AppSecurity+ Certification Exam (Android Edition) ADR-001 covers the following domains:

  1. Mobile application security, SDLC, and threat models
  2. Android SDK, APIs, and security features
  3. Web service and network security
  4. Data security and implementing encryption
  5. Application hardening and reverse engineering 5%
  6. Secure Java coding

The successful candidate should have the knowledge and skills to:

  • Describe fundamental principles of application security
  • Describe the security model of Android devices
  • Describe common threats to mobile application security
  • Develop moderately complex applications using the Android SDK
  • Describe Web services security model and vulnerabilities
  • Properly implement SSL/TLS for Web communications
  • Utilize the security features of the Android operating system and APIs
  • Properly implement secure coding techniques
  • Avoid insecure retention of data in memory
  • Describe common implementations of cryptography such as PKI
  • Leverage encryption for storage and/or communications
  • Understand access control and file permissions
  • Harden an application against attack to levels appropriate for the risk model of the application

For more information and detailed exam objectives, please refer to CompTIA’s official website.

Comments
* The most recent comment are at the top

Interesting posts

SAP Certification Exams: SAP HANA Fundamentals and Applications

Hey there! In our fast-paced digital world, SAP certifications are here to give your career a serious boost, no matter where you’re starting from. Whether you’re just getting your feet wet or you’re already a pro, these certifications validate your skills and give you the recognition you deserve. The whole idea behind the SAP certification… Read More »

Quantum Computing Fundamentals: Qiskit Certification Exam Explained

Ever heard of computers capable of solving problems in minutes that would take regular computers years? That’s the mind-bending promise of quantum computing! It’s a whole new way of using computers, and it’s opening doors in medicine, materials science, and beyond. Intrigued? If you are curious about quantum computing and want to get hands-on experience… Read More »

Cloud-Native Development: CKAD Certification Exam Preparation Guide

In today’s fast-evolving tech landscape, cloud-native development has become a pivotal skill for IT professionals. The Certified Kubernetes Application Developer (CKAD) certification is a highly sought-after credential that validates your ability to design, build, and run applications on Kubernetes. This guide will walk you through everything you need to know to prepare for the CKAD… Read More »

Certifications in Quantum Computing: Introducing New and Upcoming Certifications in the Field of Quantum Computing and Their Potential Impact

Imagine super-powered computers that can solve problems impossible for today’s machines! That is what quantum computing promises. As this mind-blowing tech becomes more real, there is a growing need for people who understand it. Here is the good news: some companies and schools are offering certificates, like mini-degrees, in quantum computing. These programs teach you… Read More »

Wireless Security Essentials: CWSP Certification Exam Insights

Hey there, tech enthusiasts and cybersecurity pros! If you’ve ever wondered how to beef up your credentials in the world of wireless security, you might want to consider the Certified Wireless Security Professional (CWSP) certification. This isn’t just another piece of paper to frame on your wall – it’s a deep dive into the nuts… Read More »

Impact of AI and Machine Learning on IT Certifications: How AI is influencing IT Certification Courses and Exams

The tech world is like a never-ending game of upgrades, and IT certifications are no exception. With Artificial Intelligence (AI) and Machine Learning (ML) taking over everything these days, it’s no surprise they are shaking things up in the world of IT training. As these technologies keep evolving, they are seriously influencing IT certifications, changing… Read More »

img