nerdexam
EC-Council

312-50V12 · Question #157

You are a cybersecurity consultant for a global organization. The organization has adopted a Bring Your Own Device (BYOD)policy, but they have recently experienced a phishing incident where an employe

The correct answer is C. Implement a mobile device management solution that restricts the installation of non-approved. To mitigate phishing risks from third-party apps on BYODs while preserving user autonomy, the organization should implement a mobile device management (MDM) solution.

Submitted by minji_kr· Mar 4, 2026Wireless Network, Mobile, IoT, and OT Hacking

Question

You are a cybersecurity consultant for a global organization. The organization has adopted a Bring Your Own Device (BYOD)policy, but they have recently experienced a phishing incident where an employee's device was compromised. In the investigation, you discovered that the phishing attack occurred through a third-party email app that the employee had installed. Given the need to balance security and user autonomy under the BYOD policy, how should the organization mitigate the risk of such incidents? Moreover, consider a measure that would prevent similar attacks without overly restricting the use of personal devices.

Options

  • AProvide employees with corporate-owned devices for work-related tasks.
  • BRequire all employee devices to use a company-provided VPN for internet access.
  • CImplement a mobile device management solution that restricts the installation of non-approved
  • DConduct regular cybersecurity awareness training, focusing on phishing attacks.

How the community answered

(48 responses)
  • A
    17% (8)
  • B
    4% (2)
  • C
    71% (34)
  • D
    8% (4)

Why each option

To mitigate phishing risks from third-party apps on BYODs while preserving user autonomy, the organization should implement a mobile device management (MDM) solution.

AProvide employees with corporate-owned devices for work-related tasks.

Providing corporate-owned devices eliminates the BYOD policy altogether and removes user autonomy, which the question specifically states needs to be balanced with security.

BRequire all employee devices to use a company-provided VPN for internet access.

A company-provided VPN secures network traffic but does not prevent the installation of malicious or unapproved applications on the device itself, which was the vector for the phishing attack.

CImplement a mobile device management solution that restricts the installation of non-approvedCorrect

Implementing a mobile device management (MDM) solution allows the organization to enforce policies that restrict the installation of non-approved applications on personal devices, directly addressing the risk posed by the third-party email app that caused the incident. This strategy enhances security by controlling the application ecosystem on BYODs used for work, while still allowing employees to use their personal devices, thereby balancing security needs with user autonomy.

DConduct regular cybersecurity awareness training, focusing on phishing attacks.

While regular cybersecurity awareness training is vital, it is a preventative measure relying on user vigilance and does not technically enforce restrictions on app installations, which was the direct cause of the incident.

Concept tested: BYOD security with Mobile Device Management (MDM) application control

Source: https://learn.microsoft.com/en-us/mem/intune/apps/app-management

Topics

#BYOD security#Mobile Device Management (MDM)#phishing prevention#mobile security

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice