Of the choices given, which one identifies the security risk of enabling Bluetooth discoverability in "visible to all" mode on a mobile device in a public place?
- A.A device in "visible to all" discoverability mode broadcasts its Bluetooth device name and class in response to inquiry scans from any nearby device; this allows device enumeration (identifying the device model and user name often included in the device name) and enables targeted pairing attempts. Social engineering attacks can then try to establish unwanted connections.
- B.Discoverability opens a remote code execution path with no pairing step (an inquiry response may carry a crafted service record the stack parses); a nearby attacker can run code on the handset without any user interaction and without a bond. The exposure is severe on every release that answers an inquiry scan from an unpaired peer in the vicinity. The risk is highest on a handset in visible mode.
- C.Modern handsets never broadcast a device name in response to an inquiry (the reply may carry the Bluetooth address alone); an attacker enumerating a room collects addresses that the platform rotates on a schedule and learns nothing about the owner. The visible-to-all setting is a legacy control the settings pane still exposes.