nerdexam
CompTIA

CAS-001 · Question #221

A corporate executive lost their smartphone while on an overseas business trip. The phone was equipped with file encryption and secured with a strong passphrase. The phone contained over 60GB of…

The correct answer is B. Immediately implement a plan to remotely wipe all data from the device. A lost encrypted smartphone still requires a remote wipe because encryption alone does not guarantee permanent data security against a determined adversary.

Enterprise Security

Question

A corporate executive lost their smartphone while on an overseas business trip. The phone was equipped with file encryption and secured with a strong passphrase. The phone contained over 60GB of proprietary data. Given this scenario, which of the following is the BEST course of action?

Options

  • AFile an insurance claim and assure the executive the data is secure because it is encrypted.
  • BImmediately implement a plan to remotely wipe all data from the device.
  • CHave the executive change all passwords and issue the executive a new phone.
  • DExecute a plan to remotely disable the device and report the loss to the police.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    79% (23)
  • C
    7% (2)
  • D
    10% (3)

Why each option

A lost encrypted smartphone still requires a remote wipe because encryption alone does not guarantee permanent data security against a determined adversary.

AFile an insurance claim and assure the executive the data is secure because it is encrypted.

Relying solely on encryption without wiping leaves the data at persistent risk if the passphrase is compromised or the encryption implementation has flaws.

BImmediately implement a plan to remotely wipe all data from the device.Correct

Remote wiping immediately destroys all data on the device, eliminating any future risk regardless of whether the encryption is eventually bypassed. While strong encryption adds a layer of protection, keys can potentially be brute-forced or the device exploited through vulnerabilities. A remote wipe is the only action that guarantees the 60GB of proprietary data cannot be recovered by an unauthorized party.

CHave the executive change all passwords and issue the executive a new phone.

Changing passwords and issuing a new phone addresses account access but does not remove the proprietary data that physically remains on the lost device.

DExecute a plan to remotely disable the device and report the loss to the police.

Remotely disabling the device renders it unusable but does not erase the stored data, which could still be extracted by removing the storage media.

Concept tested: Mobile device management remote wipe policy

Source: https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe

Topics

#mobile device management#remote wipe#data protection#incident response

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice