CAS-001 · Question #255
In order to reduce cost and improve employee satisfaction, a large corporation has decided to allow personal communication devices to access email and to remotely connect to the corporate network…
The correct answer is A. A device lockdown according to policies E. Encrypt data in transit for remote access. This is a BYOD (Bring Your Own Device) scenario. (A) Device lockdown according to policies - typically enforced via Mobile Device Management (MDM) - ensures personal devices meet minimum security baselines (screen lock, patching, no jailbreak, etc.) before being granted access…
Question
In order to reduce cost and improve employee satisfaction, a large corporation has decided to allow personal communication devices to access email and to remotely connect to the corporate network. Which of the following security measures should the IT organization implement? (Select TWO).
Options
- AA device lockdown according to policies
- BAn IDS on the internal networks
- CA data disclosure policy
- DA privacy policy
- EEncrypt data in transit for remote access
How the community answered
(65 responses)- A91% (59)
- B2% (1)
- C3% (2)
- D5% (3)
Explanation
This is a BYOD (Bring Your Own Device) scenario. (A) Device lockdown according to policies - typically enforced via Mobile Device Management (MDM) - ensures personal devices meet minimum security baselines (screen lock, patching, no jailbreak, etc.) before being granted access to corporate resources. Without this, any compromised personal device becomes a direct threat to the corporate network. (E) Encrypting data in transit for remote access (e.g., VPN or TLS) protects corporate data as it travels over untrusted personal or public networks. These two controls together address the primary risks: the uncontrolled state of personal devices and the insecurity of transit channels. An IDS (B) on internal networks is a detective measure that doesn't address BYOD-specific risks. A data disclosure policy (C) and privacy policy (D) are important governance documents but are administrative controls - they do not technically enforce security on personal devices.
Topics
Community Discussion
No community discussion yet for this question.