CAS-001 · Question #27
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the company's internal network. The Chief Information Security Officer (CISO) was…
The correct answer is C. Encryption of the non-volatile memory and a password or PIN to access the device. If the CEO's mobile device is lost or stolen, the primary security concerns are unauthorized access to the device and exposure of sensitive data stored on it. Technical controls rather than policy reminders provide effective protection in this scenario.
Question
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and wants to connect it to the company's internal network. The Chief Information Security Officer (CISO) was told to research and recommend how to secure this device. Which of the following recommendations should be implemented to keep the device from posing a security risk to the company?
Options
- AA corporate policy to prevent sensitive information from residing on a mobile device and anti-virus software.
- BEncryption of the non-volatile memory and a corporate policy to prevent sensitive information from
- CEncryption of the non-volatile memory and a password or PIN to access the device.
- DA password or PIN to access the device and a corporate policy to prevent sensitive information from
How the community answered
(22 responses)- B5% (1)
- C91% (20)
- D5% (1)
Why each option
If the CEO's mobile device is lost or stolen, the primary security concerns are unauthorized access to the device and exposure of sensitive data stored on it. Technical controls rather than policy reminders provide effective protection in this scenario.
Relying on a corporate policy to prevent sensitive data on the device does not technically enforce that restriction, and antivirus software does not protect data if the device is physically lost.
Encryption of non-volatile memory combined with a policy lacks a technical access control - a policy alone cannot prevent someone who finds the device from accessing it without a PIN or password requirement.
Encrypting non-volatile memory protects sensitive data stored on the device from being accessed if the device is lost or stolen by rendering it unreadable without the decryption key, while a password or PIN ensures that an unauthorized person cannot unlock and use the device, together forming a layered technical defense for device loss scenarios.
A PIN combined with a policy provides access control but leaves stored data unprotected if the PIN is bypassed or the storage is removed and accessed directly without encryption.
Concept tested: Mobile device encryption and authentication controls
Source: https://csrc.nist.gov/publications/detail/sp/800-124/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.