nerdexam
CompTIA

CAS-001 · Question #231

The sales division within a large organization purchased touch screen tablet computers for all 250 sales representatives in an effort to showcase the use of technology to its customers and increase…

The correct answer is C. Work with the business to understand and classify the risk associated with the full lifecycle of the. When upper management overrides a security objection and proceeds with a non-standard deployment, the most valuable response is to work with the business to understand and classify risk across the full device and application lifecycle - procurement, use, data handling, support…

Integration of Computing, Communications and Business Disciplines

Question

The sales division within a large organization purchased touch screen tablet computers for all 250 sales representatives in an effort to showcase the use of technology to its customers and increase productivity. This includes the development of a new product tracking application that works with the new platform. The security manager attempted to stop the deployment because the equipment and application are non-standard and unsupported within the organization. However, upper management decided to continue the deployment. Which of the following provides the BEST method for evaluating the potential threats?

Options

  • AConduct a vulnerability assessment to determine the security posture of the new devices and the
  • BBenchmark other organization's that already encountered this type of situation and apply all relevant
  • CWork with the business to understand and classify the risk associated with the full lifecycle of the
  • DDevelop a standard image for the new devices and migrate to a web application to eliminate locally

How the community answered

(50 responses)
  • A
    28% (14)
  • B
    14% (7)
  • C
    52% (26)
  • D
    6% (3)

Explanation

When upper management overrides a security objection and proceeds with a non-standard deployment, the most valuable response is to work with the business to understand and classify risk across the full device and application lifecycle - procurement, use, data handling, support gaps, and disposal. This produces a structured risk register that documents what the organization is accepting or must mitigate, and it aligns security with business outcomes rather than just blocking the initiative. Option A (vulnerability assessment) is useful but only captures a technical snapshot at a point in time and misses business-context risks. Option B (benchmarking) is reactive and may not match this organization's environment. Option D (standard image / web app migration) is a mitigating action, not a threat-evaluation method - and the question asks for evaluation, not remediation.

Topics

#risk management#mobile devices#lifecycle management#BYOD

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice