Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Android ATC
Exam Format
Registration
Validity
AND-402 Exam Topics and Domains
AND-402 is organized into 4 weighted domains. Expect to work with Package Manager, Permission Framework, Activity Manager, Application Framework, and more.
Permissions
Android Platform and Security Architecture
- Understand Android's layered architecture
- Identify security mechanisms at each layer
- Recognize how architecture supports security model
Application Signing and Installation
- Understand APK signing requirements
- Recognize certificate validation process
- Identify installation security mechanisms
Permission Levels and Protection
- Distinguish between four permission protection levels
- Identify when each protection level applies
- Understand permission granting mechanisms
Application-Level Permissions
- Request permissions correctly in manifest
- Identify common system permissions
- Understand permission groups
Component-Level Permissions
- Apply permissions to Activities, Services, Content Providers, Broadcast Receivers
- Understand component-specific permission mechanisms
- Implement fine-grained access control
Extending Android Permissions
- Create and define custom permissions
- Implement runtime permission handling
- Configure cross-app permission sharing
Managing the Policy File (AndroidManifest.xml)
The Manifest File Structure
- Understand manifest file structure
- Identify security-critical manifest attributes
- Configure application-level settings
Modifying Application Policy
- Configure sharedUserId correctly
- Understand shared UID security implications
- Declare application permissions properly
External Storage and Permissions
- Configure external storage permissions
- Understand scoped storage model
- Control component export and access
Debugging and Backup Configuration
- Configure debugging flags appropriately
- Implement secure backup strategies
- Understand backup security risks
Users' Data Privacy and Protection
Data Security Principles (CIA Triad)
- Understand CIA triad principles
- Apply confidentiality, integrity, availability to Android apps
- Identify security principle violations
The Mobile Environment
- Understand mobile environment complexity
- Identify stakeholders in mobile security
- Recognize multi-party security responsibilities
Data States and Vulnerabilities
- Identify three data states
- Recognize vulnerabilities for each state
- Implement state-appropriate security
Protection Principles and Best Practices
- Apply protection principles
- Avoid common coding vulnerabilities
- Implement defense-in-depth strategies
- Use permissions for data protection
Securing Storage
Data Storage Decisions
- Make appropriate storage decisions
- Consider privacy in storage choices
- Implement data retention policies
SharedPreferences
- Use SharedPreferences correctly
- Apply MODE_PRIVATE for security
- Encrypt sensitive preferences
File Storage (Internal and External)
- Distinguish internal vs external storage
- Use getExternalFilesDir() correctly
- Implement secure file storage
- Understand storage permissions
Cache Storage
- Use cache storage appropriately
- Understand cache persistence limitations
- Implement cache management
SQLite Database Storage
- Implement SQLite databases securely
- Prevent SQL injection
- Use Content Providers for data sharing
- Apply database encryption
Storage Mechanism Selection
- Select appropriate storage mechanisms
- Match storage to security requirements
- Optimize storage choices
How do I earn this certification?
Passing AND-402 earns the Android Security Essentials Certified certification. It sits in the Android Application Engineering track.
- AND-801 - Android Application Development Covers Android app development fundamentals
- AND-803 - Android Applications UI/UX Design and Monetization Techniques Covers Android UI/UX design and app monetization strategies
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
Use the official PlanetCert Practice Test alongside the study plan below to prepare efficiently for AND-402.
What's changed on this exam?
- ACTIVE
- Last content update: 2018-01-01
- Android Permissions Model Android 8.x (Oreo) in exam Core permission concepts remain the same, but runtime permissions have evolved
- Data Storage Android 8.x storage model Fundamental storage security principles unchanged; scoped storage adds restrictions
- Application Security Architecture Android 8.x architecture Core security architecture concepts are timeless
Who should take this exam?
This exam is typically taken by Android application developers and Mobile security professionals.
- Basic Android application development knowledge
- 6-12 months of Android development experience
- Completion of Android Application Development course (recommended)