1D0-610 · Question #89
Carlos is the Information Technology (iT) administrator for a small company. Over the past year, employees have been using their personal mobile devices and smart phones for business use. This has…
The correct answer is C. Create a policy that specifies acceptable use, ensuring security measures are in place for mobile devices. Option C is correct because a formal Mobile Device Management (MDM) policy - covering acceptable use, required security measures like encryption, remote wipe, and password enforcement - directly addresses the core BYOD vulnerability: uncontrolled, inconsistent security across…
Question
Carlos is the Information Technology (iT) administrator for a small company. Over the past year, employees have been using their personal mobile devices and smart phones for business use. This has reduced costs of purchasing new devices for employees. Carlos is now considering whether he should stop supplying employees with company phones and instead require all employees to use their personal smart phones for work. How can Carlos address the most significant security vu inerrability?
Options
- ADevelop a robust app to push security updates out to the various mobile OS devices
- BCreate an employee policy that requires employees to keep phones updated to the latest technology
- CCreate a policy that specifies acceptable use, ensuring security measures are in place for mobile devices
- DMandate that employees switch to the company's mobile service provider to ensure security policies
How the community answered
(32 responses)- A6% (2)
- B22% (7)
- C56% (18)
- D16% (5)
Explanation
Option C is correct because a formal Mobile Device Management (MDM) policy - covering acceptable use, required security measures like encryption, remote wipe, and password enforcement - directly addresses the core BYOD vulnerability: uncontrolled, inconsistent security across personally-owned devices. Option A is wrong because you cannot push updates to personal devices the company doesn't own or manage; employees control their own OS. Option B is insufficient on its own - a vague "keep it updated" policy doesn't enforce encryption, app restrictions, or data separation, which are the real risks. Option D is impractical and doesn't solve the security problem; changing carriers has no bearing on device-level security controls.
Memory tip: Think "Policy before technology" - on security exams, a comprehensive written policy that mandates specific controls is almost always the right first answer for BYOD scenarios, because it establishes the legal and procedural framework that all technical solutions depend on.
Topics
Community Discussion
No community discussion yet for this question.