CAS-001 · Question #293
An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to each person. Which…
The correct answer is D. Require a PIN and automatic wiping of the smartphone if someone enters a specific number of incorrect. The question specifically asks about protecting 'resident data' - data stored locally on the device. A PIN combined with automatic remote/local wiping after a set number of failed attempts directly protects data at rest: if the device is lost or stolen and an attacker attempts…
Question
An organization determined that each of its remote sales representatives must use a smartphone for email access. The organization provides the same centrally manageable model to each person. Which of the following mechanisms BEST protects the confidentiality of the resident data?
Options
- ARequire dual factor authentication when connecting to the organization's email server.
- BRequire each sales representative to establish a PIN to access the smartphone and limit email storage
- CRequire encrypted communications when connecting to the organization's email server.
- DRequire a PIN and automatic wiping of the smartphone if someone enters a specific number of incorrect
How the community answered
(48 responses)- A15% (7)
- B4% (2)
- C6% (3)
- D75% (36)
Explanation
The question specifically asks about protecting 'resident data' - data stored locally on the device. A PIN combined with automatic remote/local wiping after a set number of failed attempts directly protects data at rest: if the device is lost or stolen and an attacker attempts to brute-force the PIN, the device wipes itself before the data can be accessed. Option A (dual-factor for server connection) protects data in transit to the server but not data already stored on the device. Option B (PIN + limiting storage) is weaker than auto-wipe and relies on storage limits rather than destruction of data. Option C (encrypted communications) protects data in transit only. Auto-wipe ensures that even a physically compromised device cannot expose its resident data.
Topics
Community Discussion
No community discussion yet for this question.