CAS-001 · Question #117
A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has…
The correct answer is B. Compliance may not be supported by all smartphones. C. Equipment loss, theft, and data leakage. F. Not all smartphones natively support encryption. The correct answers are B, C, and F. B - Compliance may not be supported by all smartphones: MDM (Mobile Device Management) policies such as screen lockout and PIN enforcement are not uniformly supported across all smartphone models, OS versions, and manufacturers. Some devices…
Question
A health service provider is considering the impact of allowing doctors and nurses access to the internal email system from their personal smartphones. The Information Security Officer (ISO) has received a technical document from the security administrator explaining that the current email system is capable of enforcing security policies to personal smartphones, including screen lockout and mandatory PINs. Additionally, the system is able to remotely wipe a phone if reported lost or stolen. Which of the following should the Information Security Officer be MOST concerned with based on this scenario? (Select THREE).
Options
- AThe email system may become unavailable due to overload.
- BCompliance may not be supported by all smartphones.
- CEquipment loss, theft, and data leakage.
- DSmartphone radios can interfere with health equipment.
- EData usage cost could significantly increase.
- FNot all smartphones natively support encryption.
- GSmartphones may be used as rogue access points.
How the community answered
(37 responses)- A16% (6)
- B46% (17)
- D27% (10)
- E8% (3)
- G3% (1)
Explanation
The correct answers are B, C, and F. B - Compliance may not be supported by all smartphones: MDM (Mobile Device Management) policies such as screen lockout and PIN enforcement are not uniformly supported across all smartphone models, OS versions, and manufacturers. Some devices may silently fail to enforce policies. C - Equipment loss, theft, and data leakage: Healthcare data is extremely sensitive (HIPAA). Personal smartphones are more likely to be lost or left unattended than corporate devices, and even with remote wipe, there is a window of exposure. F - Not all smartphones natively support encryption: If a device does not support encryption, sensitive email data stored locally is exposed if the device is lost or stolen. The remote wipe capability mentioned partially addresses C and F, but does not eliminate the risk. Options A, D, E, and G are either unlikely or not the primary security concerns in this specific scenario.
Topics
Community Discussion
No community discussion yet for this question.