A user reports being billed for in-app purchases they did not make on their Android device. Which combination of controls best prevents unauthorized in-app purchase fraud on a shared device?
- A.A. Enable Google Play Protect scanning and disable sideloading
- B.B. Require purchase authentication for every transaction via Google Play settings and enable Family Library restrictions
- C.C. Enable screen lock and disable NFC
- D.D. Uninstall the affected app and reinstall from a backup
Why B is correct
Google Play's 'Require authentication for purchases' setting (Settings > Require authentication > For all purchases) enforces biometric or PIN confirmation for every in-app purchase, preventing unauthorized charges on a shared device. Family Library restrictions further limit which accounts can authorize spending. Google Play Protect scans for malware but does not prevent authorized-session purchase abuse. Screen lock and NFC state do not affect in-app billing authentication. Reinstalling the app does not change the underlying billing authentication policy.
Know someone studying for Mobile Security Fundamentals? Send them this one.