Courseiva
hardMultiple Choice

220-1202 Practice Question: During a security audit, a technician discovers…

During a security audit, a technician discovers that a company Android device has an app that can read SMS messages and access contacts without the user's knowledge. The app was sideloaded. What built-in Android security feature could have prevented this?

⚠ Common exam trap

In this question, the trap is to think that any security feature like Verified Boot or Android Device Manager would prevent sideloading. However, only Play Protect actively scans apps for suspicious behavior and excessive permissions, regardless of installation source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Google Play Protect

Google Play Protect is the correct answer because it is Android's built-in security feature that scans apps for malicious behavior, including those sideloaded from outside the Play Store. It can block or warn about apps that request excessive permissions like reading SMS and accessing contacts without user knowledge. This feature would have prevented the malicious app from being installed or alerted the user before installation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Samsung Knox

    Why it's wrong here

    Samsung Knox is vendor-specific hardening on Samsung hardware, not a built-in Android feature available across devices, so it cannot be the generic answer. It is tempting because Knox does enforce app permissions and secure boot, and it would be correct on a managed Samsung fleet rather than a general Android device.

  • ✓

    Google Play Protect

    Why this is correct

    Google Play Protect scans sideloaded APKs for malware and harmful behaviour before and after installation, satisfying the stem's sideloading constraint. Unlike the Play Store's review process, which only vets distributed apps, Play Protect actively warns or blocks installation of apps requesting dangerous combinations such as SMS and contacts access, preventing silent data harvesting.

  • ✗

    Android Device Manager

    Why it's wrong here

    Android Device Manager locates, locks and wipes lost devices; it does not vet app installation sources or restrict permissions. It is tempting because it is a built-in security-adjacent tool, and it would be the right answer for recovering or remotely erasing a misplaced handset, not for blocking a sideloaded app.

  • ✗

    Verified Boot

    Why it's wrong here

    Verified Boot checks system partition integrity at startup; it does not govern sideloaded app installation or runtime permissions. It is tempting because it is a genuine built-in Android security mechanism, and it would be correct for detecting tampered system images, not for preventing an unknown-source app from reading SMS and contacts.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.