CAS-001 · Question #130
The Chief Information Officer (CIO) of a technology company is likely to move away from a de- perimeterized model for employee owned devices. This is because there were too many issues with lack of…
The correct answer is B. Update the policy to disallow non-company end-point devices on the corporate network. The de-perimeterized/BYOC model was adopted for user preference (different OSes and app stacks), but it introduced three concrete, documented security failures: lack of patching, malware incidents, and data leakage from unencrypted lost/stolen devices. These are not policy…
Question
The Chief Information Officer (CIO) of a technology company is likely to move away from a de- perimeterized model for employee owned devices. This is because there were too many issues with lack of patching, malware incidents, and data leakage due to lost/stolen devices which did not have full-disk encryption. The `bring your own computing' approach was originally introduced because different business units preferred different operating systems and application stacks. Based on the issues and user needs, which of the following is the BEST recommendation for the CIO to make?
Options
- AThe de-perimeterized model should be kept as this is major industry trend and other companies
- BUpdate the policy to disallow non-company end-point devices on the corporate network.
- CThe de-perimeterized model should be kept but update company policies to state that non-company
- DUpdate the policy to disallow non-company end-point devices on the corporate network.
How the community answered
(58 responses)- A5% (3)
- B62% (36)
- C10% (6)
- D22% (13)
Explanation
The de-perimeterized/BYOC model was adopted for user preference (different OSes and app stacks), but it introduced three concrete, documented security failures: lack of patching, malware incidents, and data leakage from unencrypted lost/stolen devices. These are not policy failures - they are inherent technical risks of unmanaged, employee-owned hardware. The most effective remediation is to prohibit non-company devices from the corporate network (Option B), which eliminates the attack surface entirely. This allows the company to regain control over endpoint patch state, malware defenses, and disk encryption requirements. Option A dismisses proven failures because of industry trends - poor security reasoning. Option C suggests keeping the model and updating policies, but the problems experienced (no patching, no FDE) are compliance failures that policies alone cannot enforce on devices the company does not own or manage. Note: Options B and D have identical text - both represent the correct answer.
Topics
Community Discussion
No community discussion yet for this question.