Concept and mechanism
Mobile attack surface includes local components and network trust. In Android, exported determines whether a component can be invoked outside the application, subject to other platform and permission conditions. For a strictly internal activity, explicit false avoids reliance on varying defaults; same-UID and privileged components have documented exceptions. In network configuration, debug-overrides applies only when the app is debuggable. A CA in that section is not added through that mechanism when the artifact sets false. Inspection should use the final artifact because development and distribution configuration can differ.
Guided application
In fictional technical facilities, an OT controller communicates only during a weekly batch. Two hours of passive observation cannot establish complete inventory. Combine traffic, records, and authorized inspection; identify silent assets and unobserved segments. Passive observation adds no probes but still requires appropriate access and data handling. Active probes against sensitive devices need prior validation and operational coordination, preferably during suitable maintenance. The final NIST guidance used here is revision three; revision four remains an initial draft. Do not automatically transfer IT-server practices to controllers with different physical-safety and availability requirements.
Final Android artifact and observed OT traffic: two pieces of evidence with explicit scopes.
Common pitfalls
Universal defaults; debug as production; silence as nonexistence; ping as scan tolerance.
Related topics: Scope, authorization, and risk reporting · Reconnaissance and observation limits · Systems, vulnerabilities, and evidence
Verify what was distributed and what the environment tolerates.
Reference: OT security · CEH 312-50, Exam Blueprint v5.0 effective2024-04-10; Candidate Handbook v7.3 (2026-09-21)