1D0-61C · Question #65
You are a small-business owner and would like to encourage employees to bring their own devices (BYOD) to work. Which of the following can help reduce the security risks associated with a BYOD…
The correct answer is B. Acceptable use policy. Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan…
Question
You are a small-business owner and would like to encourage employees to bring their own devices (BYOD) to work. Which of the following can help reduce the security risks associated with a BYOD implementation?
Options
- AExpense accounts
- BAcceptable use policy
- CEnd user license agreement
- DIn-house device maintenance
How the community answered
(19 responses)- B89% (17)
- C5% (1)
- D5% (1)
Explanation
Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan: First Test, First Pass. Help you to pass any IT Certification exams at the first try. You can reach us at any of the email addresses listed below. Any problems about IT certification or our products, you could rely upon us, we will give you satisfactory answers in 24 hours.
Topics
Community Discussion
9B is the answer here, and this one trips people up because they overthink the technical angle when the question is actually asking about policy. An acceptable use policy sets the ground rules for how employees can use their personal devices on company networks, what data they can access, and what behaviors are prohibited, which directly reduces the risk surface of a BYOD rollout. Expense accounts just cover costs, EULAs are agreements between a user and a software vendor, and in-house device maintenance does not scale to personal hardware you do not even own. If you see a BYOD question on 1D0-61C and it asks about reducing risk through governance or rules, AUP should jump out at you immediately. This question style shows up consistently in the security and business policy sections, so get comfortable spotting it.
Saw this exact style of question on mine and the key is thinking about what actually governs employee behavior on personal devices rather than what handles software licensing or finances. Did anyone else get tripped up wondering whether a policy counts as a "security control" or just a piece of paper?
Toby nailed the framing but the "just a piece of paper" trap cuts both ways, because on the exam a policy absolutely is a security control, it just happens to be an administrative one rather than a technical one.
Almost marked D, but my AUP card locked this one in.
That instinct to pause and trace it back to the AUP is exactly the habit that saves you on the tricky distractors, though it is worth also knowing which AUP violation triggers which response, since some questions will split those apart.
An acceptable use policy sets the ground rules for how personal devices interact with company systems, which is really the first control layer before you even think about technical enforcement. When you frame BYOD governance around documented user expectations rather than reactive restrictions, does your organization treat the policy as a living document that employees actually review, or is it a one-time onboarding signature that nobody revisits?
That living-document framing is exactly right, and the part that trips people up on the exam is remembering that periodic re-acknowledgment tied to a version history is what actually gives the AUP legal and audit weight, not just the intent to keep it updated.
C makes sense because EULAs govern how personal devices may be used on your network.
Hey Grace, EULAs actually cover the terms between a software vendor and the end user for a specific application, not how personal devices are permitted on an organizational network. That falls under an Acceptable Use Policy, which is why B is the right pick here.