nerdexam
EC-Council

312-50V13 · Question #594

As a cybersecurity analyst for a large corporation, you are auditing the company's mobile device management (MDM) policy. One of your areas of concern is data leakage from company- provided…

The correct answer is D. Enforce a policy that only allows app installations from approved corporate app stores. To prevent data leakage via malicious apps on company-provided smartphones, enforcing app installations only from approved corporate app stores is an effective measure.

Submitted by diego_uy· Mar 6, 2026Hacking Mobile Platforms

Question

As a cybersecurity analyst for a large corporation, you are auditing the company's mobile device management (MDM) policy. One of your areas of concern is data leakage from company- provided smartphones. You are worried about employees unintentionally installing malicious apps that could access sensitive corporate data on their devices. Which of the following would be an effective measure to prevent such data leakage?

Options

  • ARequire biometric authentication for unlocking devices.
  • BRegularly change Wi-Fi passwords used by the devices.
  • CMandate the use of VPNs when accessing corporate data.
  • DEnforce a policy that only allows app installations from approved corporate app stores.

How the community answered

(29 responses)
  • A
    14% (4)
  • B
    3% (1)
  • C
    10% (3)
  • D
    72% (21)

Why each option

To prevent data leakage via malicious apps on company-provided smartphones, enforcing app installations only from approved corporate app stores is an effective measure.

ARequire biometric authentication for unlocking devices.

Requiring biometric authentication secures device access but does not prevent a legitimate user from installing a malicious app that subsequently accesses corporate data while the device is unlocked.

BRegularly change Wi-Fi passwords used by the devices.

Regularly changing Wi-Fi passwords improves network access security but does not directly address the risk of malicious apps already installed on devices accessing local data.

CMandate the use of VPNs when accessing corporate data.

Mandating VPNs secures data in transit to corporate resources but does not prevent a malicious app on the device from accessing data stored locally on the device or exfiltrating it via other means.

DEnforce a policy that only allows app installations from approved corporate app stores.Correct

Enforcing a policy that restricts app installations to only approved corporate app stores (or whitelisted apps) significantly reduces the risk of employees installing malicious or unvetted applications that could contain malware, access sensitive corporate data, or exfiltrate information. This provides a controlled environment for mobile applications, reducing the attack surface.

Concept tested: Mobile Device Management (MDM) app control

Source: https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy

Topics

#Mobile device management#Data leakage#Mobile security#App whitelisting

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice