nerdexam
CompTIA

CAS-001 · Question #413

A large hospital has implemented BYOD to allow doctors and specialists the ability to access patient medical records on their tablets. The doctors and specialists access patient records over the…

The correct answer is A. Privacy could be compromised as patient records can be viewed in uncontrolled areas. D. Malware may be on BYOD devices which can extract data via key logging and screen scrapes. Even though the architecture is well-designed (remote desktop, 2FA, no copy/paste, network isolation), two significant residual risks remain. First (A): the remote desktop interface renders sensitive patient records visually on the BYOD device screen. A doctor reviewing records…

Enterprise Security

Question

A large hospital has implemented BYOD to allow doctors and specialists the ability to access patient medical records on their tablets. The doctors and specialists access patient records over the hospital's guest WiFi network which is isolated from the internal network with appropriate security controls. The patient records management system can be accessed from the guest network and requires two factor authentication. Using a remote desktop type interface, the doctors and specialists can interact with the hospital's system. Cut and paste and printing functions are disabled to prevent the copying of data to BYOD devices. Which of the following are of MOST concern? (Select TWO).

Options

  • APrivacy could be compromised as patient records can be viewed in uncontrolled areas.
  • BDevice encryption has not been enabled and will result in a greater likelihood of data loss.
  • CThe guest WiFi may be exploited allowing non-authorized individuals access to confidential
  • DMalware may be on BYOD devices which can extract data via key logging and screen scrapes.
  • ERemote wiping of devices should be enabled to ensure any lost device is rendered inoperable.

How the community answered

(56 responses)
  • A
    70% (39)
  • B
    4% (2)
  • C
    20% (11)
  • E
    7% (4)

Explanation

Even though the architecture is well-designed (remote desktop, 2FA, no copy/paste, network isolation), two significant residual risks remain. First (A): the remote desktop interface renders sensitive patient records visually on the BYOD device screen. A doctor reviewing records in a coffee shop, hospital lobby, or other uncontrolled public area exposes Protected Health Information (PHI) to shoulder surfing and unintended observers-a direct HIPAA privacy violation. Second (D): because BYOD devices are personally owned and unmanaged by the hospital's IT security team, they may harbor malware. Keyloggers can capture credentials and any text typed, while screen-capture malware can photograph the remote desktop session in real time, completely bypassing the copy/paste restrictions. Device encryption (B) is less relevant since patient data is not stored locally. WiFi exploitation (C) is mitigated by the described security controls. Remote wiping (E) is less critical since patient data does not reside on the device.

Topics

#BYOD#mobile security#privacy#malware keylogging

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice