nerdexam
CompTIA

CAS-001 · Question #208

Within a large organization, the corporate security policy states that personal electronic devices are not allowed to be placed on the company network. There is considerable pressure from the…

The correct answer is B. Review the security policy. Perform a risk evaluation of allowing devices that can be centrally. Option B best balances security and usability by first reviewing the policy and performing a formal risk evaluation focused on devices that can be centrally managed (e.g., enrolled in MDM/EMM with remote wipe, policy enforcement, and encryption). This approach is risk-based…

Integration of Computing, Communications and Business Disciplines

Question

Within a large organization, the corporate security policy states that personal electronic devices are not allowed to be placed on the company network. There is considerable pressure from the company board to allow smartphones to connect and synchronize email and calendar items of board members and company executives. Which of the following options BEST balances the security and usability requirements of the executive management team?

Options

  • AAllow only the executive management team the ability to use personal devices on the company
  • BReview the security policy. Perform a risk evaluation of allowing devices that can be centrally
  • CStand firm on disallowing non-company assets from connecting to the network as the assets may
  • DAllow only certain devices that are known to have the ability of being centrally managed.

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    54% (20)
  • C
    30% (11)
  • D
    11% (4)

Explanation

Option B best balances security and usability by first reviewing the policy and performing a formal risk evaluation focused on devices that can be centrally managed (e.g., enrolled in MDM/EMM with remote wipe, policy enforcement, and encryption). This approach is risk-based rather than absolute, aligns with business needs, and maintains governance. Simply allowing only executives (A) creates inconsistent security without proper risk controls. Refusing all requests (C) ignores legitimate business need and fails the usability requirement. Allowing only centrally manageable devices (D) is closer but skips the formal risk evaluation and policy review step that ensures the decision is documented and defensible.

Topics

#BYOD policy#mobile device management#security policy#risk evaluation

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice